Reflected XSS Vulnerability in WP-Lister Lite for eBay
CVE-2024-47380
7.1HIGH
Summary
A reflected Cross-site Scripting (XSS) vulnerability exists in WP Lab's WP-Lister Lite for eBay plugin, affecting versions up to and including 3.6.3. This vulnerability arises from improper neutralization of user input during the generation of web pages, allowing attackers to inject malicious scripts. Successful exploitation can lead to unauthorized access and data manipulation within affected web applications. It is crucial for users of the plugin to apply security patches to mitigate this issue and protect sensitive information.
Affected Version(s)
WP-Lister Lite for eBay <= 3.6.3
References
CVSS V3.1
Score:
7.1
Severity:
HIGH
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Changed
Timeline
Vulnerability published
Vulnerability Reserved
Credit
Le Ngoc Anh (Patchstack Alliance)