Reflected Cross-Site Scripting in iBuildApp WordPress Plugin by iBuildApp
CVE-2024-13326
Key Information:
- Vendor
- iBuildApp
- Status
- Ibuildapp
- Vendor
- CVE Published:
- 4 February 2025
Badges
Summary
The iBuildApp WordPress plugin fails to properly sanitize and escape user input, allowing attackers to execute reflected cross-site scripting (XSS) attacks. This vulnerability can be exploited by malicious actors to inject and execute arbitrary JavaScript code in the context of a victim's browser session. Notably, high-privileged users, such as administrators, are at increased risk, as the attack can lead to unauthorized actions and data compromise. Website administrators should promptly update to the fixed versions to safeguard against potential exploits.
Affected Version(s)
iBuildApp 0 <= 0.2.0
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.
References
CVSS V3.1
Timeline
- 🟡
Public PoC available
- 👾
Exploit known to exist
Vulnerability published
Vulnerability Reserved