Reflected XSS Vulnerability in The Ultimate WordPress Toolkit - WP Extended
CVE-2024-37259
7.1HIGH
Key Information:
- Vendor
WordPress
- Vendor
- CVE Published:
- 22 July 2024
What is CVE-2024-37259?
The WP Extended The Ultimate WordPress Toolkit is susceptible to a reflected cross-site scripting (XSS) vulnerability. This occurs due to improper neutralization of input during web page generation, allowing attackers to inject malicious scripts that are executed in the browser of unsuspecting users. The vulnerability affects versions prior to 2.4.7, potentially compromising the security of websites utilizing this plugin. Ensuring proper input handling and updating to the latest version will mitigate these risks.
Affected Version(s)
The Ultimate WordPress Toolkit β WP Extended 0 <= 2.4.7
References
EPSS Score
11% chance of being exploited in the next 30 days.
CVSS V3.1
Score:
7.1
Severity:
HIGH
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Changed
Timeline
Vulnerability published
Vulnerability Reserved
Credit
Yudistira Arya (Patchstack Alliance)