Reflected XSS Vulnerability in DEV Institute's Membership Plugin
CVE-2024-29138
7.1HIGH
Key Information:
- Vendor
WordPress
- Vendor
- CVE Published:
- 19 March 2024
What is CVE-2024-29138?
A reflected XSS vulnerability exists in DEV Institute's Restrict User Access β Membership Plugin with Force, allowing attackers to inject malicious scripts via reflective web page generation. This issue can lead to unauthorized actions on behalf of users and expose sensitive information. Users of affected versions, specifically from n/a through 2.5, should take immediate steps to apply relevant security patches to mitigate potential exploitation.
Affected Version(s)
Restrict User Access β Membership Plugin with Force 0 <= 2.5