Reflected XSS Vulnerability in LH Add Media From Url
CVE-2024-32533
7.1HIGH
What is CVE-2024-32533?
A reflected cross-site scripting (XSS) vulnerability exists in the LH Add Media From Url plugin developed by Peter Shaw. This issue arises due to improper neutralization of input during web page generation. Attackers can exploit this vulnerability to inject malicious scripts into web pages, which could be executed in the context of the user's browser session. This makes users susceptible to various attacks, including data theft and session hijacking. The vulnerability specifically affects versions from n/a up to 1.22 of the LH Add Media From Url plugin.
Affected Version(s)
LH Add Media From Url <= 1.22