CVE-2024-12749: WordPress Competition Form Plugin <= 2.0 - Cross-Site Scripting
漏洞描述
Competition Form WordPress plugin <= 2.0 contains a reflected cross-site scripting caused by lack of sanitization and escaping of a parameter before outputting it in the page, letting attackers execute malicious scripts in the context of high privilege users, exploit requires victim to visit a maliciously crafted page. [已公开] id: CVE-2024-12749 info: name: WordPress Competition Form Plugin <= 2.0 - Cross-Site Scripting author: Sourabh-Sahu severity: high description: | Competition Form WordPress plugin <= 2.0 contains a reflected cross-site scripting caused by lack of sanitization and escaping of a parameter before outputting it in the page, letting attackers execute malicious scripts in the context of high privilege users, exploit requires victim to visit a maliciously crafted page. impact: | Attackers can execute malicious scripts in the context of high privilege users, potentially leading to session hijacking or privilege escalation. remediation: | Update to the latest version of the plugin where the issue is fixed. reference: - https://wpscan.com/vulnerability/478316b9-9f47-4aa6-92c6-03879f16a3e5/ - https://nvd.nist.gov/vuln/detail/CVE-2024-12749 classification: cvss-metrics: CV
影响范围
未知
修复建议
暂无