XSS Vulnerability in GEO my WordPress
CVE-2024-47327

7.1HIGH

Key Information:

Vendor
Wordpress
Vendor
CVE Published:
6 October 2024

Summary

A vulnerability exists within GEO my WordPress, which allows for reflected cross-site scripting (XSS) due to the improper neutralization of user input during web page generation. Attackers can exploit this flaw to inject malicious scripts into the web pages served to users, potentially leading to unauthorized actions or data theft. This issue affects all versions from 'n/a' up to and including version 4.5.0.3 of the GEO my WordPress plugin.

Affected Version(s)

GEO my WordPress <= 4.5.0.3

References

CVSS V3.1

Score:
7.1
Severity:
HIGH
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Le Ngoc Anh (Patchstack Alliance)
.