Reflected Cross-Site Scripting Vulnerability in WhatsApp Click to Chat Plugin for WordPress
CVE-2024-11686
6.1MEDIUM
What is CVE-2024-11686?
The WhatsApp Click to Chat plugin for WordPress lacks proper input sanitization and output escaping, specifically within the 'manycontacts_code' parameter. This vulnerability allows unauthenticated attackers to exploit the plugin by executing arbitrary web scripts in the context of user interactions, potentially leading to harmful actions if users are tricked into clicking malicious links. All versions up to and including 3.0.4 are affected, making it crucial for users to remain vigilant and update their installations.
Affected Version(s)
WhatsApp π click to chat * <= 3.0.4