Reflected XSS Vulnerability in Tobias Conrad CF7 WOW Styler
CVE-2024-51689

7.1HIGH

Key Information:

Vendor
WordPress
Vendor
CVE Published:
9 November 2024

Summary

A reflected cross-site scripting vulnerability exists in the CF7 WOW Styler plugin developed by Tobias Conrad. This flaw arises from improper neutralization of input during web page generation, permitting an attacker to inject malicious scripts. The vulnerability can be exploited by sending crafted requests to affected installations, leading to potential execution of arbitrary JavaScript in the context of the user’s browser. Users interacting with compromised links may unknowingly expose sensitive information or deviate from intended web functionality. This issue is present in versions up to and including 1.6.8. Vigilance in security practices and timely updates to the affected plugin are crucial for mitigation.

Affected Version(s)

CF7 WOW Styler <= 1.6.8

References

CVSS V3.1

Score:
7.1
Severity:
HIGH
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Le Ngoc Anh (Patchstack Alliance)
.