Stored Cross-Site Scripting Vulnerability in wpDiscuz Plugin
CVE-2024-2477
5.4MEDIUM
What is CVE-2024-2477?
The wpDiscuz plugin for WordPress has a vulnerability that allows for Stored Cross-Site Scripting through the 'Alternative Text' field of uploaded images. This issue arises due to inadequate input sanitization and output escaping, enabling authenticated users with author-level access or higher to inject arbitrary scripts. When a user accesses a page containing these injected scripts, the malicious web code will execute, potentially compromising the security of the site and its users.
Affected Version(s)
Comments – wpDiscuz * <= 7.6.15