Stored XSS Vulnerability in GD Rating System
CVE-2024-25093
6.1MEDIUM
Key Information:
- Vendor
WordPress
- Status
- Vendor
- CVE Published:
- 29 February 2024
What is CVE-2024-25093?
The GD Rating System developed by Milan Petrovic is susceptible to a significant vulnerability that permits stored cross-site scripting (XSS) attacks due to improper neutralization of inputs during web page generation processes. This issue, affecting all versions from n/a through 3.5, allows attackers to inject malicious scripts that can be stored and executed in the user's browser, compromising the security and integrity of the application as well as potentially leading to data theft and unauthorized actions performed on behalf of legitimate users.
Affected Version(s)
GD Rating System <= 3.5