Stored XSS Vulnerability in Dyn Business Panel Plugin for WordPress
CVE-2024-13057
Key Information:
- Vendor
- WordPress
- Status
- Vendor
- CVE Published:
- 27 January 2025
Badges
Summary
The Dyn Business Panel WordPress plugin version 1.0.0 is vulnerable due to the absence of CSRF checks in certain functions, along with inadequate sanitization and escaping mechanisms. This flaw can permit attackers to exploit the vulnerability and inject Stored XSS payloads through CSRF attacks, potentially compromising the security of logged-in admin users. It is crucial for webmasters to update the plugin and implement necessary security measures to mitigate risks associated with this vulnerability.
Affected Version(s)
Dyn Business Panel 0 <= 1.0.0
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.
References
CVSS V3.1
Timeline
- π‘
Public PoC available
- πΎ
Exploit known to exist
Vulnerability published
Vulnerability Reserved