Reflected Cross-Site Scripting Vulnerability in Advanced Options Editor
CVE-2024-54249

7.1HIGH

Key Information:

Vendor

WordPress

Vendor
CVE Published:
16 December 2024

What is CVE-2024-54249?

CVE-2024-54249 is a highly critical reflected cross-site scripting (XSS) vulnerability found in the Advanced Options Editor plugin by Jules Colle. This security flaw enables attackers to inject malicious scripts into web pages viewed by users. The vulnerability affects versions up to 1.0, allowing exploitation through improper input handling during page generation. Users of the plugin are advised to implement immediate countermeasures to mitigate the risks associated with this vulnerability, as it poses a significant threat to web application security.

Affected Version(s)

Advanced Options Editor <= 1.0

References

CVSS V3.1

Score:
7.1
Severity:
HIGH
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Le Ngoc Anh (Patchstack Alliance)
.