Reflected Cross-Site Scripting Vulnerability in Custom Banners plugin
CVE-2024-8799
What is CVE-2024-8799?
The Custom Banners plugin for WordPress contains a vulnerability that allows unauthenticated attackers to exploit reflected Cross-Site Scripting (XSS) weaknesses. Due to inadequate escaping in the handling of URL parameters with the add_query_arg function, attackers can craft malicious links that, when clicked by unsuspecting users, could lead to the execution of arbitrary web scripts within the context of the user’s browser. This vulnerability affects all versions of the plugin up to and including 3.3, posing significant risks to end-users by potentially exposing their sessions and sensitive data.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
Custom Banners * <= 3.3
References
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved