Reflected XSS Vulnerability in WP-Lister Lite for eBay
CVE-2024-47380

7.1HIGH

Key Information:

Vendor
WordPress
Vendor
CVE Published:
5 October 2024

Summary

A reflected Cross-site Scripting (XSS) vulnerability exists in WP Lab's WP-Lister Lite for eBay plugin, affecting versions up to and including 3.6.3. This vulnerability arises from improper neutralization of user input during the generation of web pages, allowing attackers to inject malicious scripts. Successful exploitation can lead to unauthorized access and data manipulation within affected web applications. It is crucial for users of the plugin to apply security patches to mitigate this issue and protect sensitive information.

Affected Version(s)

WP-Lister Lite for eBay <= 3.6.3

References

CVSS V3.1

Score:
7.1
Severity:
HIGH
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Le Ngoc Anh (Patchstack Alliance)
.