Stored Cross-Site Scripting Vulnerability in WP Githuber MD by Terry Lin
CVE-2024-52422

5.4MEDIUM

Key Information:

Vendor

WordPress

Vendor
CVE Published:
18 November 2024

What is CVE-2024-52422?

The WP Githuber MD plugin developed by Terry Lin is susceptible to a Stored Cross-Site Scripting (XSS) vulnerability. This flaw occurs due to improper neutralization of user inputs during the web page generation process. As a result, an attacker could exploit this weakness to inject malicious scripts into content that could be stored and subsequently executed in the browsers of users interacting with affected versions of the plugin. This issue poses significant risks to the security and integrity of web applications utilizing this plugin.

References

CVSS V3.1

Score:
5.4
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

.