Reflected XSS Vulnerability in Featured Posts with Multiple Custom Groups
CVE-2024-48032
7.1HIGH
Key Information:
- Vendor
- Sumit Surai
- Status
- Featured Posts With Multiple Custom Groups (fpmcg)
- Vendor
- CVE Published:
- 17 October 2024
Summary
The vulnerability associated with the Featured Posts with Multiple Custom Groups plugin poses a risk through improper neutralization of input when generating web pages. This reflected cross-site scripting (XSS) issue allows attackers to inject malicious scripts, which can be executed in the context of a user's session. Users of the affected versions of the plugin are potentially at risk, as the vulnerability may be exploited to compromise personal information or facilitate further attacks.
Affected Version(s)
Featured Posts with Multiple Custom Groups (FPMCG) <= 4.0
References
CVSS V3.1
Score:
7.1
Severity:
HIGH
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Changed
Timeline
Vulnerability published
Vulnerability Reserved
Credit
Mika (Patchstack Alliance)