XSS Vulnerability in Metagauss RegistrationTeam RegistrationMagic
CVE-2024-43317

4.3MEDIUM

Key Information:

Vendor

WordPress

Vendor
CVE Published:
19 August 2024

What is CVE-2024-43317?

The vulnerability in Metagauss RegistrationMagic plugin arises from improper neutralization of input during the web page generation process, specifically leading to Cross-Site Scripting (XSS). This issue allows attackers to inject malicious scripts into web pages viewed by other users, potentially compromising user data and website integrity. Affected versions include those from n/a through 6.0.1.0, necessitating immediate attention and remediation to secure the user registration functionality against XSS attacks.

Affected Version(s)

RegistrationMagic <= 6.0.1.0

References

CVSS V3.1

Score:
4.3
Severity:
MEDIUM
Confidentiality:
None
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

.