Reflected Cross-Site Scripting Vulnerability in WhatsApp Click to Chat Plugin for WordPress
CVE-2024-11686

6.1MEDIUM

Key Information:

Vendor

Wordpress

Vendor
CVE Published:
9 January 2025

What is CVE-2024-11686?

The WhatsApp Click to Chat plugin for WordPress lacks proper input sanitization and output escaping, specifically within the 'manycontacts_code' parameter. This vulnerability allows unauthenticated attackers to exploit the plugin by executing arbitrary web scripts in the context of user interactions, potentially leading to harmful actions if users are tricked into clicking malicious links. All versions up to and including 3.0.4 are affected, making it crucial for users to remain vigilant and update their installations.

Affected Version(s)

WhatsApp πŸš€ click to chat * <= 3.0.4

References

CVSS V3.1

Score:
6.1
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Dale Mavers
.