Reflected XSS Vulnerability in DirectoryPress by Designinvento
CVE-2024-49633

6.1MEDIUM

Key Information:

Vendor

WordPress

Vendor
CVE Published:
7 January 2025

What is CVE-2024-49633?

The DirectoryPress plugin developed by Designinvento is prone to a reflected cross-site scripting (XSS) vulnerability. When user input is not properly sanitized during web page generation, attackers can exploit this flaw to inject malicious scripts into the web pages served by DirectoryPress. This vulnerability affects all versions from its inception up to 3.6.19, potentially allowing unauthorized actions to be performed by users, leading to compromised sessions or data exposure. It is crucial for website owners using DirectoryPress to apply updates and implement robust security measures to mitigate the risk associated with this vulnerability.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.

Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.

Affected Version(s)

DirectoryPress <= 3.6.19

References

CVSS V3.1

Score:
6.1
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Dimas Maulana (Patchstack Alliance)
.