Stored Cross-Site Scripting Vulnerability in HurryTimer for WordPress
CVE-2024-13735

5.4MEDIUM

Key Information:

Summary

The HurryTimer plugin for WordPress, used for creating scarcity and urgency countdown timers, is prone to a Stored Cross-Site Scripting vulnerability. This weakness arises from inadequate sanitization of input and output associated with campaign names. Authenticated users, such as those with Contributor-level access and above, can exploit this flaw to insert arbitrary scripts into pages that are viewed by users. Consequently, this can lead to unauthorized actions and sensitive data exposure if a user accesses an affected page.

Affected Version(s)

HurryTimer – An Scarcity and Urgency Countdown Timer for WordPress & WooCommerce * <= 2.11.2

References

CVSS V3.1

Score:
5.4
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

D.Sim
.