Reflected XSS Vulnerability in wp-mpdf
CVE-2024-27962

6.1MEDIUM

Key Information:

Vendor
WordPress
Status
Vendor
CVE Published:
21 March 2024

Summary

The vulnerability in the WP-MPDF Plugin for WordPress is characterized by improper neutralization of user input during web page generation, leading to reflected Cross-site Scripting (XSS) attacks. This issue can be exploited by attackers to inject malicious scripts into web pages viewed by other users. Affecting versions from n/a through 3.7.1, this vulnerability poses a risk to user data and overall site integrity, as it enables unauthorized access and manipulation of content once users visit the compromised page.

Affected Version(s)

wp-mpdf <= 3.7.1

References

CVSS V3.1

Score:
6.1
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

stealthcopter (Patchstack Alliance)
.