Reflected XSS Vulnerability in Spice Starter Sites
CVE-2024-44003

7.1HIGH

Key Information:

Vendor

WordPress

Vendor
CVE Published:
18 September 2024

What is CVE-2024-44003?

A Cross-site Scripting vulnerability has been identified in SpiceThemes' Spice Starter Sites plugin, which allows attackers to inject malicious scripts through improperly sanitized user inputs. This makes it possible for an attacker to execute arbitrary JavaScript in the context of a user's browser session, potentially leading to unauthorized actions or data theft. The affected versions range from n/a to 1.2.5, and it is crucial for users to apply recommended security patches to protect their sites from exploitation.

Affected Version(s)

Spice Starter Sites 0 <= 1.2.5

References

CVSS V3.1

Score:
7.1
Severity:
HIGH
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

.