Fabrica Synced Pattern Instances Vulnerable to Reflected XSS
CVE-2024-51695

7.1HIGH

Key Information:

Vendor

WordPress

Vendor
CVE Published:
9 November 2024

What is CVE-2024-51695?

A vulnerability exists in Fabrica Synced Pattern Instances that allows for reflected Cross-site Scripting (XSS) attacks due to improper neutralization of user inputs during web page generation. This flaw can potentially be exploited by malicious actors to inject arbitrary scripts into the web page, leading to the compromise of user interactions and data security. The affected versions include those prior to 1.0.8, making it crucial for users and administrators to apply necessary patches and update to the latest version to mitigate any potential threats.

Affected Version(s)

Fabrica Synced Pattern Instances <= 1.0.8

References

CVSS V3.1

Score:
7.1
Severity:
HIGH
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

João Pedro Soares de Alcântara - Kinorth (Patchstack Alliance)
.