Reflected XSS Vulnerability in Featured Posts with Multiple Custom Groups
CVE-2024-48032

7.1HIGH

Key Information:

Vendor
Sumit Surai
Status
Featured Posts With Multiple Custom Groups (fpmcg)
Vendor
CVE Published:
17 October 2024

Summary

The vulnerability associated with the Featured Posts with Multiple Custom Groups plugin poses a risk through improper neutralization of input when generating web pages. This reflected cross-site scripting (XSS) issue allows attackers to inject malicious scripts, which can be executed in the context of a user's session. Users of the affected versions of the plugin are potentially at risk, as the vulnerability may be exploited to compromise personal information or facilitate further attacks.

Affected Version(s)

Featured Posts with Multiple Custom Groups (FPMCG) <= 4.0

References

CVSS V3.1

Score:
7.1
Severity:
HIGH
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Mika (Patchstack Alliance)
.