VYPR
Medium severity6.5NVD Advisory· Published May 6, 2024· Updated Apr 28, 2026

CVE-2024-34376

CVE-2024-34376

Description

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Theme Freesia Edge allows Stored XSS.This issue affects Edge: from n/a through 2.0.9.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Stored XSS in Theme Freesia Edge WordPress theme through version 2.0.9 allows attackers to inject arbitrary scripts.

Vulnerability

The Theme Freesia Edge WordPress theme, versions from n/a through 2.0.9, contains a stored cross-site scripting (XSS) vulnerability due to improper neutralization of user input during web page generation [1]. The issue stems from insufficient sanitization of input fields, allowing malicious scripts to be stored and later executed when other users view the affected pages.

Exploitation

An attacker with contributor-level access or higher can inject malicious JavaScript code into input fields that are not properly sanitized. The injected script becomes stored in the application's data and is subsequently rendered on pages viewed by other users, including administrators. No special network position is required beyond normal authenticated access to the WordPress admin interface.

Impact

Successful exploitation allows the attacker to execute arbitrary JavaScript in the context of a victim's browser. This can lead to session hijacking, defacement, or redirection to malicious sites. The attacker does not gain direct server-level access but can compromise the security of other users interacting with the affected theme.

Mitigation

Users should update the Edge theme to version 2.1.2 or later, as this update addresses the vulnerability [1]. If immediate update is not possible, consider restricting contributor and author roles or disabling user registration. As of the publication date, no known workarounds are documented beyond patching.

References
  1. Edge

AI Insight generated on May 23, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.

Affected products

2

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

1

News mentions

0

No linked articles in our index yet.