Stored Cross-Site Scripting Vulnerability in Easy Waveform Player for WordPress

CVE-2024-11881

6.4MEDIUM

Key Information:

Vendor
WordPress
Vendor
CVE Published:
18 December 2024

Summary

The Easy Waveform Player plugin for WordPress is susceptible to a Stored Cross-Site Scripting (XSS) vulnerability through its 'easywaveformplayer' shortcode. This security flaw, present in all versions up to and including 1.2.0, arises from the plugin's failure to properly sanitize and escape user-supplied input. As a result, authenticated attackers with contributor-level access and higher can exploit this weakness to inject arbitrary web scripts into pages. When a user accesses such an affected page, the injected scripts execute, potentially leading to unauthorized actions or data breaches. Website administrators are strongly advised to update the plugin to the latest version and implement robust security measures to mitigate these risks.

References

CVSS V3.1

Score:
6.4
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

Collectors

NVD Database
.