YITH Custom Login Plugin Vulnerable to Reflected Cross-Site Scripting
CVE-2024-8665

6.1MEDIUM

Key Information:

Vendor

WordPress

Vendor
CVE Published:
13 September 2024

What is CVE-2024-8665?

The YITH Custom Login plugin for WordPress contains a vulnerability that allows for Reflected Cross-Site Scripting (XSS). This issue arises from the improper use of the add_query_arg function without adequate escaping in the URL parameters. As a consequence, unauthenticated attackers can craft malicious links that may exploit this vulnerability. When a user is manipulated into clicking such a link, harmful scripts could be executed within their browser, compromising their session or divulging sensitive information. All versions of the YITH Custom Login plugin up to and including version 1.7.3 are affected, raising significant security concerns for WordPress site administrators and users alike.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.

Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.

Affected Version(s)

YITH Custom Login * <= 1.7.3

References

CVSS V3.1

Score:
6.1
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Dale Mavers
.