VYPR
Medium severity5.9NVD Advisory· Published Jul 22, 2024· Updated Apr 23, 2026

CVE-2024-37422

CVE-2024-37422

Description

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Progress Planner Progress Planner progress-planner.This issue affects Progress Planner: from n/a through <= 0.9.2.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Stored cross-site scripting vulnerability in WordPress Progress Planner plugin up to version 0.9.2 allows attackers with privileged access to inject malicious scripts.

Vulnerability

Description

In the WordPress Progress Planner plugin versions 0.9.2 and earlier, user input is not properly sanitized before being stored, leading to a stored cross-site scripting (XSS) vulnerability [1][2]. This occurs due to improper neutralization of input during web page generation, allowing arbitrary script injection.

Exploitation

Exploitation requires a privileged user (such as an administrator) to perform an action, like clicking a malicious link or visiting a crafted page [1][2]. Once the script is injected, it is stored and executed when any visitor accesses the affected page.

Impact

An attacker can inject malicious scripts (e.g., redirects, advertisements, data theft) into the WordPress site [1][2]. This can lead to further compromise of users or the site itself, and the vulnerability is considered moderately dangerous and likely to be targeted in mass campaigns.

Mitigation

The vulnerability is patched in version 0.9.3 of the plugin [1][2]. Users are advised to update immediately. Patchstack has released mitigation rules to block attacks until the update is applied.

AI Insight generated on May 20, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.

Affected products

1

Patches

1

Vulnerability mechanics

Generated on May 9, 2026. Inputs: CWE entries + fix-commit diffs from this CVE's patches. Citations validated against bundle.

References

2

News mentions

0

No linked articles in our index yet.