Reflected XSS Vulnerability in Evergreen Content Poster
CVE-2024-29099

6.1MEDIUM

Key Information:

Vendor
WordPress
Vendor
CVE Published:
19 March 2024

Summary

The Evergreen Content Poster plugin for WordPress contains a reflected cross-site scripting (XSS) vulnerability that arises from the improper neutralization of user input during web page generation. This flaw enables attackers to inject malicious scripts into webpages viewed by unsuspecting users. When users interact with the compromised pages or follow manipulated links, they may inadvertently execute harmful scripts. This type of attack can lead to severe implications, including data theft and session hijacking, raising significant concerns for web application security.

Affected Version(s)

Evergreen Content Poster <= 1.4.1

References

CVSS V3.1

Score:
6.1
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Joshua Chan (Patchstack Alliance)
.