Cross-Site Scripting Vulnerability in WP-Lister Lite for eBay by WordPress
CVE-2024-43306

7.1HIGH

Key Information:

Vendor

WordPress

Vendor
CVE Published:
18 August 2024

What is CVE-2024-43306?

A reflected Cross-Site Scripting (XSS) vulnerability exists in WP-Lister Lite for eBay, which allows an attacker to inject malicious scripts into web pages viewed by users. This can lead to unauthorized actions and data exposure, as users may unknowingly execute the harmful scripts while interacting with the affected plugin. The issue specifically affects all versions from n/a through 3.6.0, making it critical for users to update or apply necessary security measures.

Affected Version(s)

WP-Lister Lite for eBay 0 <= 3.6.0

References

CVSS V3.1

Score:
7.1
Severity:
HIGH
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

.