Reflected XSS Vulnerability in Enfold
CVE-2024-37199

7.1HIGH

Key Information:

Vendor

WordPress

Status
Vendor
CVE Published:
22 July 2024

What is CVE-2024-37199?

The Enfold Theme by Kriesi contains a vulnerability that allows for the execution of reflected cross-site scripting (XSS) attacks due to improper neutralization of input during web page generation. Attackers can exploit this flaw by injecting malicious scripts, which can lead to various impacts on affected users, including session hijacking and data theft. Users of Enfold Theme versions up to 5.6.9 should take immediate action to mitigate potential risks associated with this vulnerability.

Affected Version(s)

Enfold <= 5.6.9

References

CVSS V3.1

Score:
7.1
Severity:
HIGH
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

tom (Patchstack Alliance)
.