Cross-Site Scripting Vulnerability in CF7 File Download by Rimes Gold
CVE-2024-33697
5.9MEDIUM
Key Information:
- Vendor
WordPress
- Vendor
- CVE Published:
- 26 April 2024
What is CVE-2024-33697?
The CF7 File Download plugin by Rimes Gold contains a vulnerability that allows for improper neutralization of input during web page generation, leading to Stored Cross-Site Scripting (XSS) attacks. This issue can enable attackers to inject malicious scripts into web pages viewed by other users, potentially compromising user data and site integrity. The vulnerability affects versions n/a through 2.0, making it critical for users to apply patches as soon as possible to mitigate these risks.
Affected Version(s)
CF7 File Download β File Download for CF7 <= 2.0