YITH Custom Login Plugin Vulnerable to Reflected Cross-Site Scripting
CVE-2024-8665
What is CVE-2024-8665?
The YITH Custom Login plugin for WordPress contains a vulnerability that allows for Reflected Cross-Site Scripting (XSS). This issue arises from the improper use of the add_query_arg function without adequate escaping in the URL parameters. As a consequence, unauthenticated attackers can craft malicious links that may exploit this vulnerability. When a user is manipulated into clicking such a link, harmful scripts could be executed within their browser, compromising their session or divulging sensitive information. All versions of the YITH Custom Login plugin up to and including version 1.7.3 are affected, raising significant security concerns for WordPress site administrators and users alike.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
YITH Custom Login * <= 1.7.3
References
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved