Stored XSS Vulnerability in Featured Posts Scroll
CVE-2024-51647

7.1HIGH

Key Information:

Vendor

WordPress

Vendor
CVE Published:
9 November 2024

What is CVE-2024-51647?

A Cross-Site Request Forgery (CSRF) vulnerability exists in the Featured Posts Scroll plugin developed by Chaser324. This flaw enables adversaries to manipulate requests made by authenticated users, potentially leading to the injection of malicious scripts and resulting in Stored Cross-Site Scripting (XSS) attacks. Affected versions range from unspecified to 1.25, posing a significant risk to users who integrate this plugin within their WordPress sites. It is crucial for website administrators to apply necessary security patches and updates to safeguard against potential exploitation of this vulnerability.

Affected Version(s)

Featured Posts Scroll <= 1.25

References

CVSS V3.1

Score:
7.1
Severity:
HIGH
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

SOPROBRO (Patchstack Alliance)
.