WordPress WPZOOM Shortcodes Plugin <= 1.0.3 is vulnerable to Cross Site Scripting (XSS)
CVE-2024-22162

7.1HIGH

Key Information:

Vendor

WordPress

Vendor
CVE Published:
31 January 2024

What is CVE-2024-22162?

The WPZOOM Shortcodes plugin for WordPress has a vulnerability that exposes web applications to Cross-Site Scripting (XSS) attacks. This issue arises from improper handling of user input during web page generation, which can be exploited to execute arbitrary scripts in the context of a user’s browser. Attackers can inject malicious code into pages that are fetched by unsuspecting users, allowing them to steal sensitive information or perform actions on behalf of the victim.

Affected Version(s)

WPZOOM Shortcodes <= 1.0.3

References

CVSS V3.1

Score:
7.1
Severity:
HIGH
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Dhabaleshwar Das (Patchstack Alliance)
.