Stored Cross-Site Scripting Vulnerability in HurryTimer for WordPress
CVE-2024-13735

5.4MEDIUM

What is CVE-2024-13735?

The HurryTimer plugin for WordPress, used for creating scarcity and urgency countdown timers, is prone to a Stored Cross-Site Scripting vulnerability. This weakness arises from inadequate sanitization of input and output associated with campaign names. Authenticated users, such as those with Contributor-level access and above, can exploit this flaw to insert arbitrary scripts into pages that are viewed by users. Consequently, this can lead to unauthorized actions and sensitive data exposure if a user accesses an affected page.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.

Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.

Affected Version(s)

HurryTimer – An Scarcity and Urgency Countdown Timer for WordPress & WooCommerce * <= 2.11.2

References

CVSS V3.1

Score:
5.4
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

D.Sim
.