Stored Cross-Site Scripting Vulnerability in ProfileGrid Plugin
CVE-2024-8861
Key Information:
- Vendor
Wordpress
- Vendor
- CVE Published:
- 26 September 2024
What is CVE-2024-8861?
The ProfileGrid β User Profiles, Groups and Communities plugin for WordPress has a vulnerability that allows for Stored Cross-Site Scripting due to the improper implementation of the wp_kses_allowed_html function. This flaw exists in all versions up to and including 5.9.3.2. It permits authenticated users with Contributor-level access and above to exploit the system by injecting malicious web scripts into pages. These scripts will execute whenever an affected page is accessed by any user, potentially compromising the security of the website and its users.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
ProfileGrid β User Profiles, Groups and Communities * <= 5.9.3.2
References
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved