Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Kemory Grubb Recencio Book Reviews allows DOM-Based XSS.This issue affects Recencio Book Reviews: from n/a through 1.66.0.
Advisories
Source ID Title
EUVD EUVD EUVD-2024-31364 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in wzy Media Recencio Book Reviews allows Stored XSS.This issue affects Recencio Book Reviews: from n/a through 1.66.0.
Fixes

Solution

Update the WordPress Recencio Book Reviews plugin to the latest available version (at least 1.70.0). Note: This is an unofficial patch (reference link), and it is important to note that the repository is maintained by a third party. Patchstack has validated the specific commit at the request of the community, as the original plugin author is unable to provide an update.


Workaround

No workaround given by the vendor.

History

Tue, 17 Feb 2026 13:00:00 +0000

Type Values Removed Values Added
Description Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in wzy Media Recencio Book Reviews allows Stored XSS.This issue affects Recencio Book Reviews: from n/a through 1.66.0. Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Kemory Grubb Recencio Book Reviews allows DOM-Based XSS.This issue affects Recencio Book Reviews: from n/a through 1.66.0.
References

Projects

Sign in to view the affected projects.

cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-02-17T12:40:22.274Z

Reserved: 2024-04-25T09:19:09.422Z

Link: CVE-2024-33648

cve-icon Vulnrichment

Updated: 2024-08-02T02:36:04.465Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2024-04-29T05:15:07.580

Modified: 2026-02-17T13:16:16.770

Link: CVE-2024-33648

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.

Weaknesses