VYPR
High severity7.1NVD Advisory· Published May 17, 2024· Updated Apr 15, 2026

CVE-2024-34752

CVE-2024-34752

Description

Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in PluginOps Landing Page Builder allows Reflected XSS.This issue affects Landing Page Builder: from n/a through 1.5.1.8.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Reflected XSS in PluginOps Landing Page Builder for WordPress (up to 1.5.1.8) allows unauthenticated attackers to inject arbitrary scripts via improper input neutralization.

The PluginOps Landing Page Builder plugin for WordPress contains a reflected cross-site scripting (XSS) vulnerability due to improper neutralization of user-supplied input during web page generation [1]. This flaw exists in versions from n/a through 1.5.1.8, where the plugin fails to sanitize or escape certain parameters before including them in the page output, enabling injection of malicious HTML and JavaScript [1].

Exploitation requires user interaction: an attacker can craft a malicious link or URL containing the injected script and trick a privileged user (e.g., an administrator) into clicking it or submitting a crafted form [1]. No authentication is needed for the attacker beyond the ability to deliver the malicious link, making this suitable for mass-exploit campaigns targeting thousands of WordPress sites simultaneously [1].

If successfully exploited, an attacker can execute arbitrary scripts in the context of the victim's browser session. This can lead to redirects, serving of advertisements, theft of session cookies, or other unauthorized actions that affect both the site administrator and regular visitors [1].

The vendor recommends updating to version 1.5.1.9 or later, which contains the fix [1]. Patchstack has also issued a mitigation rule to block attacks until the update is applied [1]. Organizations unable to update immediately should consult their hosting provider or web developer for alternative workarounds.

AI Insight generated on May 20, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.

Affected products

1

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

1

News mentions

0

No linked articles in our index yet.