Reflected Cross-Site Scripting Vulnerability in Custom Banners plugin
CVE-2024-8799

6.1MEDIUM

Key Information:

Vendor
Wordpress
Vendor
CVE Published:
1 October 2024

Summary

The Custom Banners plugin for WordPress contains a vulnerability that allows unauthenticated attackers to exploit reflected Cross-Site Scripting (XSS) weaknesses. Due to inadequate escaping in the handling of URL parameters with the add_query_arg function, attackers can craft malicious links that, when clicked by unsuspecting users, could lead to the execution of arbitrary web scripts within the context of the user’s browser. This vulnerability affects all versions of the plugin up to and including 3.3, posing significant risks to end-users by potentially exposing their sessions and sensitive data.

Affected Version(s)

Custom Banners * <= 3.3

References

CVSS V3.1

Score:
6.1
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Dale Mavers
.