Stored Cross-Site Scripting Vulnerability in SEO Themes Simple Pricing Table
CVE-2024-51899

6.5MEDIUM

Key Information:

Vendor

WordPress

Vendor
CVE Published:
19 November 2024

What is CVE-2024-51899?

The SEO Themes Simple Pricing Table plugin is affected by a Stored Cross-site Scripting (XSS) vulnerability that occurs due to improper neutralization of user inputs during web page generation. This vulnerability allows an attacker to inject malicious scripts into web pages that can be stored and executed in the user’s browser, potentially leading to the compromise of user data and session hijacking. Users of affected versions are encouraged to update the plugin to mitigate potential risks.

Affected Version(s)

Simple Pricing Table 0 <= 1.0.0

References

CVSS V3.1

Score:
6.5
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

.