XSS Vulnerability in GEO my WordPress
CVE-2024-47327
7.1HIGH
Summary
A vulnerability exists within GEO my WordPress, which allows for reflected cross-site scripting (XSS) due to the improper neutralization of user input during web page generation. Attackers can exploit this flaw to inject malicious scripts into the web pages served to users, potentially leading to unauthorized actions or data theft. This issue affects all versions from 'n/a' up to and including version 4.5.0.3 of the GEO my WordPress plugin.
Affected Version(s)
GEO my WordPress <= 4.5.0.3
References
CVSS V3.1
Score:
7.1
Severity:
HIGH
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Changed
Timeline
Vulnerability published
Vulnerability Reserved
Credit
Le Ngoc Anh (Patchstack Alliance)