MoMo, ViettelPay, VNPay Plugin for WordPress Vulnerable to Stored Cross-Site Scripting
CVE-2024-8914

7.2HIGH

What is CVE-2024-8914?

The Thanh Toán Quét Mã QR Code T? ??ng plugin, utilized for payment processes in Vietnam, exhibits a Stored Cross-Site Scripting vulnerability across all versions up to 2.0.1. This flaw arises from an improper application of the wp_kses_allowed_html function, permitting the inclusion of the 'onclick' attribute in specific HTML elements without adequate restrictions or context verification. As a result, unauthenticated attackers can inject malicious web scripts into the pages, which will execute whenever users navigate to these compromised pages, posing a significant security risk.

Affected Version(s)

Thanh Toán Quét Mã QR Code Tự Động – MoMo, ViettelPay, VNPay và 40 ngân hàng Việt Nam * <= 2.0.1

References

CVSS V3.1

Score:
7.2
Severity:
HIGH
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Francesco Carlucci
.