Reflected XSS Vulnerability in Custom 404 Pro
CVE-2024-39646

7.1HIGH

Key Information:

Vendor

WordPress

Vendor
CVE Published:
1 August 2024

What is CVE-2024-39646?

A reflected cross-site scripting (XSS) vulnerability has been identified in the Kunal Nagar Custom 404 Pro plugin, allowing attackers to inject malicious scripts into the web pages rendered by the plugin. This vulnerability affects all versions up to 3.11.1, making it possible for attackers to exploit user interactions and compromise the integrity of user data. Proper input validation and sanitization measures are crucial to mitigate such risks and safeguard against potential exploitation.

Affected Version(s)

Custom 404 Pro 0 <= 3.11.1

References

CVSS V3.1

Score:
7.1
Severity:
HIGH
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

.