VYPR
Medium severity6.5NVD Advisory· Published Aug 29, 2024· Updated Jun 17, 2026No known patch

CVE-2024-43949

CVE-2024-43949

Description

Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Automattic GHActivity allows Stored XSS.This issue affects GHActivity: from n/a through 2.0.0-alpha.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected products

4
  • cpe:2.3:a:automattic:ghacitivity:2.0.0:alpha:*:*:*:wordpress:*:*
  • cpe:2.3:a:automattic:ghactivity:*:*:*:*:*:wordpress:*:*+ 1 more
    • cpe:2.3:a:automattic:ghactivity:*:*:*:*:*:wordpress:*:*range: <=1.5.0
    • (no CPE)range: n/a
  • Range: <=2.0.0-alpha

Patches

Vulnerability mechanics

References

1

News mentions

0

No linked articles in our index yet.