WordPress WOLF Plugin <= 1.0.8 is vulnerable to Cross Site Scripting (XSS)
CVE-2024-22159

7.1HIGH

What is CVE-2024-22159?

The WOLF – WordPress Posts Bulk Editor and Manager Professional plugin suffers from a Cross-site Scripting vulnerability due to improper input sanitization during web page generation. This allows attackers to inject malicious scripts that can be executed in the context of the user's browser when viewing affected pages, potentially compromising sensitive information and user sessions. The vulnerability affects versions up to 1.0.8, making it essential for users to update to secure their installations.

Affected Version(s)

WOLF – WordPress Posts Bulk Editor and Manager Professional <= 1.0.8

References

CVSS V3.1

Score:
7.1
Severity:
HIGH
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

thiennv (Patchstack Alliance)
.