Cross-Site Scripting Vulnerability in ConvertCalculator for WordPress
CVE-2024-56302

6.5MEDIUM

Key Information:

Vendor
Wordpress
Vendor
CVE Published:
2 January 2025

Summary

A security flaw exists in ConvertCalculator for WordPress that enables cross-site scripting (XSS) attacks. This vulnerability arises from improper neutralization of user input during the generation of web pages, allowing malicious users to inject and execute harmful scripts in a victim's browser. Websites using ConvertCalculator for WordPress, particularly versions up to and including 1.1.1, are susceptible. Successful exploitation can lead to unauthorized actions, data theft, or further attacks on visitors of the affected site. Website administrators are advised to review their current version and take immediate steps to mitigate this risk by updating or applying recommended security patches.

Affected Version(s)

ConvertCalculator for WordPress <= 1.1.1

References

CVSS V3.1

Score:
6.5
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

theviper17 (Patchstack Alliance)
.