Roles & Capabilities Plugin Vulnerable to Reflected Cross-Site Scripting
CVE-2024-8732
6.1MEDIUM
What is CVE-2024-8732?
The Roles & Capabilities plugin for WordPress contains a vulnerability that allows unauthenticated attackers to exploit Reflected Cross-Site Scripting. This issue arises from the improper use of the add_query_arg function, which does not effectively escape the URL. As a result, attackers could inject malicious web scripts that execute on targeted pages when a user is tricked into clicking a specially crafted link. This poses a significant risk to users and their data, highlighting the importance of updating to the latest versions and ensuring proper security measures are implemented.
Affected Version(s)
Roles & Capabilities * <= 1.1.9