Fabrica Synced Pattern Instances Vulnerable to Reflected XSS
CVE-2024-51695
7.1HIGH
Key Information:
- Vendor
WordPress
- Vendor
- CVE Published:
- 9 November 2024
What is CVE-2024-51695?
A vulnerability exists in Fabrica Synced Pattern Instances that allows for reflected Cross-site Scripting (XSS) attacks due to improper neutralization of user inputs during web page generation. This flaw can potentially be exploited by malicious actors to inject arbitrary scripts into the web page, leading to the compromise of user interactions and data security. The affected versions include those prior to 1.0.8, making it crucial for users and administrators to apply necessary patches and update to the latest version to mitigate any potential threats.
Affected Version(s)
Fabrica Synced Pattern Instances <= 1.0.8
References
CVSS V3.1
Score:
7.1
Severity:
HIGH
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Changed
Timeline
Vulnerability published
Vulnerability Reserved
Credit
João Pedro Soares de Alcântara - Kinorth (Patchstack Alliance)