Improper Neutralization of Input During Web Page Generation (Reflected XSS)
CVE-2024-54327

7.1HIGH

Key Information:

Vendor

WordPress

Status
Vendor
CVE Published:
13 December 2024

What is CVE-2024-54327?

The UNIVERSAM plugin by Universam is susceptible to a Reflected Cross-site Scripting (XSS) vulnerability due to improper neutralization of input during web page generation. Attackers can exploit this flaw to execute arbitrary scripts in the context of the user's browser, potentially leading to unauthorized actions or data theft. All versions of the UNIVERSAM plugin prior to the latest updates remain vulnerable, making it essential for users to patch their installations to mitigate risk.

Affected Version(s)

UNIVERSAM < 8.59

References

CVSS V3.1

Score:
7.1
Severity:
HIGH
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Zlrqh (Patchstack Alliance)
.