CVE-2024-37422
Description
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Progress Planner Progress Planner progress-planner.This issue affects Progress Planner: from n/a through <= 0.9.2.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Stored cross-site scripting vulnerability in WordPress Progress Planner plugin up to version 0.9.2 allows attackers with privileged access to inject malicious scripts.
Vulnerability
Description
In the WordPress Progress Planner plugin versions 0.9.2 and earlier, user input is not properly sanitized before being stored, leading to a stored cross-site scripting (XSS) vulnerability [1][2]. This occurs due to improper neutralization of input during web page generation, allowing arbitrary script injection.
Exploitation
Exploitation requires a privileged user (such as an administrator) to perform an action, like clicking a malicious link or visiting a crafted page [1][2]. Once the script is injected, it is stored and executed when any visitor accesses the affected page.
Impact
An attacker can inject malicious scripts (e.g., redirects, advertisements, data theft) into the WordPress site [1][2]. This can lead to further compromise of users or the site itself, and the vulnerability is considered moderately dangerous and likely to be targeted in mass campaigns.
Mitigation
The vulnerability is patched in version 0.9.3 of the plugin [1][2]. Users are advised to update immediately. Patchstack has released mitigation rules to block attacks until the update is applied.
AI Insight generated on May 20, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.
Affected products
1Patches
1b45a9dc540dfVulnerability mechanics
Generated on May 9, 2026. Inputs: CWE entries + fix-commit diffs from this CVE's patches. Citations validated against bundle.
References
2- patchstack.com/database/vulnerability/progress-planner/wordpress-progress-planner-plugin-0-9-2-cross-site-scripting-xss-vulnerabilitynvdThird Party Advisory
- patchstack.com/database/Wordpress/Plugin/progress-planner/vulnerability/wordpress-progress-planner-plugin-0-9-2-cross-site-scripting-xss-vulnerabilitynvd
News mentions
0No linked articles in our index yet.