Cross-Site Scripting Vulnerability in GTPayment Donations Plugin for WordPress
CVE-2024-11607
Key Information:
- Vendor
- Wordpress
- Status
- Vendor
- CVE Published:
- 21 December 2024
Badges
Summary
The GTPayment Donations WordPress plugin, up to version 1.0.0, is vulnerable to Cross-Site Scripting (XSS) attacks due to a lack of proper Cross-Site Request Forgery (CSRF) checks and insufficient input sanitization and output escaping. This vulnerability allows authenticated attackers to inject malicious scripts into the website through a CSRF exploit, which can lead to stored XSS, compromising the security of the site and its users. Administrators may unknowingly include harmful payloads, potentially leading to data theft, disruption of services, or damage to the site's integrity.
Affected Version(s)
GTPayment Donations 0 <= 1.0.0
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.
References
CVSS V3.1
Timeline
- π‘
Public PoC available
- πΎ
Exploit known to exist
Vulnerability published
Vulnerability Reserved