Reflected Cross-Site Scripting in Badgearoo WordPress Plugin by WordPress
CVE-2024-13828
Key Information:
Badges
What is CVE-2024-13828?
The Badgearoo WordPress plugin before version 1.0.14 is susceptible to a reflected cross-site scripting vulnerability. This issue arises as user input is not properly sanitized or escaped before being rendered on the web page. Attackers can exploit this oversight to inject malicious scripts, which may target high-privilege users, such as administrators. It is crucial for website owners using this plugin to implement immediate updates to safeguard their environments from potential malicious attacks.
Affected Version(s)
Badgearoo 0 <= 1.0.14
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.
References
CVSS V3.1
Timeline
- 🟡
Public PoC available
- 👾
Exploit known to exist
Vulnerability published
Vulnerability Reserved