Arbitrary Web Script Injection Vulnerability in Responsive Video Plugin for WordPress
CVE-2024-7629
Key Information:
- Vendor
- Marla14
- Status
- Responsive Video
- Vendor
- CVE Published:
- 21 August 2024
Summary
The Responsive Video Plugin for WordPress is prone to a vulnerability that allows for Stored Cross-Site Scripting (XSS) attacks. This issue arises in versions up to and including 1.0, where inadequate input sanitization and output escaping are present in the plugin's video settings function. Authenticated attackers with contributor-level access and higher can exploit this flaw to inject arbitrary web scripts into pages. When users access an affected page, these scripts can execute, leading to potential data theft or other malicious actions. It is essential for users to ensure proper security measures are implemented while using this plugin, particularly if responsive videos are enabled for posts.
Affected Version(s)
Responsive Video * <= 1.0
References
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved