Reflected Cross-Site Scripting Vulnerability in Musicbox WordPress Plugin by WPDev
CVE-2024-13327
Key Information:
- Vendor
- WPDev
- Status
- Musicbox
- Vendor
- CVE Published:
- 4 February 2025
Badges
Summary
A critical vulnerability exists in the Musicbox WordPress plugin, versions up to 2.0.3, where user input is not properly sanitized and escaped. This oversight enables attackers to craft malicious requests that can exploit high privilege users, such as administrators, by injecting harmful scripts into the web page. The lack of proper input handling could lead to session hijacking, data theft, or unauthorized actions on behalf of the user. Website owners using this plugin must take immediate action to mitigate this risk.
Affected Version(s)
Musicbox 0 <= 2.0.3
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.
References
CVSS V3.1
Timeline
- 🟡
Public PoC available
- 👾
Exploit known to exist
Vulnerability published
Vulnerability Reserved