Google Docs RSVP Cross-Site Request Forgery Vulnerability Allows Stored XSS
CVE-2024-49672

7.1HIGH

Key Information:

Vendor

WordPress

Vendor
CVE Published:
29 October 2024

What is CVE-2024-49672?

A Cross-Site Request Forgery (CSRF) vulnerability exists in the Google Docs RSVP plugin developed by Gifford Cheung. This flaw allows attackers to execute unauthorized actions on behalf of users, potentially leading to stored Cross-Site Scripting (XSS) attacks. The issue affects versions of the plugin up to and including 2.0.1, making it critical for users to update to the latest version to safeguard against potential exploits.

Affected Version(s)

Google Docs RSVP 0 <= 2.0.1

References

CVSS V3.1

Score:
7.1
Severity:
HIGH
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

.