VYPR
High severity7.1NVD Advisory· Published Oct 5, 2024· Updated Apr 23, 2026

CVE-2024-47644

CVE-2024-47644

Description

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Copyscape Copyscape Premium copyscape-premium allows Stored XSS.This issue affects Copyscape Premium: from n/a through <= 1.3.9.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Stored XSS in Copyscape Premium ≤1.3.9 allows attackers to inject arbitrary scripts via improperly neutralized input.

Vulnerability

Overview

Copyscape Premium versions up to and including 1.3.9 contain a stored cross-site scripting (XSS) vulnerability caused by improper neutralization of input during web page generation [1]. This issue allows an attacker to inject malicious scripts that are stored on the server and later executed in the browsers of users accessing the affected pages.

Exploitation

Exploitation requires a privileged user to perform an action—such as clicking a malicious link or submitting a crafted form—due to the Cross-Site Request Forgery (CSRF) vector that enables the injection [1]. The vulnerability is partially patched in versions 1.3.7 and later, but still present in the affected range [1].

Impact

An authenticated attacker with lower privileges can force higher-privileged users to execute unwanted actions under their current session, leading to data theft, defacement, or further compromise of the WordPress site [1]. The potential for mass exploitation campaigns is noted, as similar vulnerabilities are frequently targeted [1].

Mitigation

Users should update to version 1.4.0 or later to fully resolve the vulnerability [1]. Patchstack provides a mitigation rule to block attacks until the update is applied [1].

AI Insight generated on May 20, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.

Affected products

1

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

1

News mentions

0

No linked articles in our index yet.