Reflected XSS Vulnerability in ARPrice Plugin by NotFound
CVE-2024-49700
7.1HIGH
Summary
The ARPrice plugin by NotFound is susceptible to a reflected Cross-site Scripting (XSS) vulnerability. This flaw permits attackers to craft malicious input that can be executed in the user's browser upon interaction with affected web pages. Users of ARPrice versions prior to 4.0.3 may expose themselves to potential exploits if they fail to apply the necessary updates and implement sufficient input validation measures. It is crucial for website owners to remain vigilant and update their plugins to safeguard against such vulnerabilities.
Affected Version(s)
ARPrice <= 4.0.3
References
CVSS V3.1
Score:
7.1
Severity:
HIGH
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Changed
Timeline
Vulnerability published
Vulnerability Reserved
Credit
Bonds (Patchstack Alliance)