Stored Cross-Site Scripting Vulnerability Affects Code Embed Plugin for WordPress
CVE-2024-8804
5.4MEDIUM
Summary
The Code Embed plugin for WordPress has a vulnerability that allows authenticated users with contributor-level access and above to exploit the script embed functionality. This flaw stems from insufficient restrictions, enabling attackers to inject arbitrary web scripts into pages. Whenever users access these compromised pages, the injected scripts execute, which can lead to various malicious activities, including data theft and session hijacking. It is crucial for users of the Code Embed plugin to update to the latest version and implement security measures to mitigate these risks.
Affected Version(s)
Code Embed * <= 2.4
References
CVSS V3.1
Score:
5.4
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
Required
Scope:
Changed
Timeline
Vulnerability published
Vulnerability Reserved
Credit
Leo Trinh