Reflected XSS Vulnerability in wp-mpdf
CVE-2024-27962
6.1MEDIUM
Summary
The vulnerability in the WP-MPDF Plugin for WordPress is characterized by improper neutralization of user input during web page generation, leading to reflected Cross-site Scripting (XSS) attacks. This issue can be exploited by attackers to inject malicious scripts into web pages viewed by other users. Affecting versions from n/a through 3.7.1, this vulnerability poses a risk to user data and overall site integrity, as it enables unauthorized access and manipulation of content once users visit the compromised page.
Affected Version(s)
wp-mpdf <= 3.7.1
References
CVSS V3.1
Score:
6.1
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Changed
Timeline
Vulnerability published
Vulnerability Reserved
Credit
stealthcopter (Patchstack Alliance)