Unprotected URL Vulnerability Affects WPAdverts Classifieds Plugin
CVE-2024-10890
6.1MEDIUM
Key Information:
- Vendor
- Wordpress
- Vendor
- CVE Published:
- 21 November 2024
Summary
The WPAdverts - Classifieds Plugin for WordPress is susceptible to a reflected cross-site scripting issue. This vulnerability arises from inadequate input sanitization when using the add_query_arg and remove_query_arg functions on URLs. Attackers can exploit this flaw to inject malicious web scripts that execute upon user interaction, such as clicking a misleading link. The vulnerability is present in all versions prior to and including 2.1.7, which may potentially compromise the security of affected sites if users are tricked into following harmful URLs.
Affected Version(s)
WPAdverts – Classifieds Plugin * <= 2.1.7
References
CVSS V3.1
Score:
6.1
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Changed
Timeline
Vulnerability published
Vulnerability Reserved
Credit
Peter Thaleikis