Stored Cross-Site Scripting Vulnerability Affects Code Embed Plugin for WordPress
CVE-2024-8804
What is CVE-2024-8804?
The Code Embed plugin for WordPress has a vulnerability that allows authenticated users with contributor-level access and above to exploit the script embed functionality. This flaw stems from insufficient restrictions, enabling attackers to inject arbitrary web scripts into pages. Whenever users access these compromised pages, the injected scripts execute, which can lead to various malicious activities, including data theft and session hijacking. It is crucial for users of the Code Embed plugin to update to the latest version and implement security measures to mitigate these risks.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
Code Embed * <= 2.4
References
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved