Cross-Site Scripting Vulnerability in Themify Builder by Themify
CVE-2024-52423

5.4MEDIUM

Key Information:

Vendor

WordPress

Vendor
CVE Published:
18 November 2024

What is CVE-2024-52423?

The vulnerability in Themify Builder is attributed to improper handling of user input during web page generation, leading to potential Stored Cross-site Scripting (XSS) attacks. This can allow attackers to inject malicious scripts into web pages viewed by users, compromising web application security and user data. The affected versions range from n/a through 7.6.3, and users are advised to implement necessary security measures or updates to mitigate the risks associated with this vulnerability.

Affected Version(s)

Themify Builder 0 <= 7.6.5

References

CVSS V3.1

Score:
5.4
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

.