Arbitrary Web Script Injection Vulnerability in Responsive Video Plugin for WordPress
CVE-2024-7629

5.4MEDIUM

Key Information:

Vendor
Marla14
Status
Responsive Video
Vendor
CVE Published:
21 August 2024

Summary

The Responsive Video Plugin for WordPress is prone to a vulnerability that allows for Stored Cross-Site Scripting (XSS) attacks. This issue arises in versions up to and including 1.0, where inadequate input sanitization and output escaping are present in the plugin's video settings function. Authenticated attackers with contributor-level access and higher can exploit this flaw to inject arbitrary web scripts into pages. When users access an affected page, these scripts can execute, leading to potential data theft or other malicious actions. It is essential for users to ensure proper security measures are implemented while using this plugin, particularly if responsive videos are enabled for posts.

Affected Version(s)

Responsive Video * <= 1.0

References

CVSS V3.1

Score:
5.4
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

lowol ngo
.