Cross-Site Scripting Vulnerability in Garden Gnome Package for WordPress
CVE-2024-8657
What is CVE-2024-8657?
The Garden Gnome Package plugin for WordPress is susceptible to a Stored Cross-Site Scripting vulnerability caused by insufficient sanitization and escaping of user-supplied attributes within the plugin's ggpkg shortcode. This vulnerability allows authenticated attackers, including those with contributor-level access and above, to inject arbitrary scripts into web pages. The injected scripts are executed in the browser of any user who visits the affected page, potentially leading to unauthorized data manipulation or exposure.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
Garden Gnome Package * <= 2.2.9
References
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved