Reflected Cross-Site Scripting Vulnerability in Ebook Store Plugin for WordPress
CVE-2024-12262
6.1MEDIUM
What is CVE-2024-12262?
The Ebook Store plugin for WordPress has been identified as vulnerable to a reflected cross-site scripting (XSS) attack through the 'step' parameter. This vulnerability exists in all versions of the plugin up to and including version 5.8001, stemming from inadequate input sanitization and output escaping. As a result, unauthenticated attackers can inject arbitrary web scripts into pages viewed by users. This exploitation requires the attacker to trick the user into clicking a malicious link, potentially leading to unauthorized actions or data exposure on the affected website.
Affected Version(s)
Ebook Store * <= 5.8001