Plugin Vulnerable to Stored Cross-Site Scripting
CVE-2024-11727
Key Information:
- Vendor
- Wordpress
- Vendor
- CVE Published:
- 12 December 2024
Summary
The NotificationX plugin for WordPress is susceptible to a Stored Cross-Site Scripting vulnerability stemming from inadequate input sanitization and output escaping in its notification content settings. This flaw allows authenticated users with administrator-level privileges to inject arbitrary web scripts into pages, leading to execution upon user access. The vulnerability specifically affects multi-site WordPress installations and those configurations where the unfiltered_html option is disabled, potentially compromising the integrity and security of affected sites.
Affected Version(s)
NotificationX – Live Sales Notification, WooCommerce Sales Popup, FOMO, Social Proof, Announcement Banner & Floating Notification Top Bar * <= 2.9.3
References
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved