MoMo, ViettelPay, VNPay Plugin for WordPress Vulnerable to Stored Cross-Site Scripting
CVE-2024-8914
7.2HIGH
Key Information:
- Vendor
WordPress
- Vendor
- CVE Published:
- 25 September 2024
What is CVE-2024-8914?
The Thanh Toán Quét Mã QR Code T? ??ng plugin, utilized for payment processes in Vietnam, exhibits a Stored Cross-Site Scripting vulnerability across all versions up to 2.0.1. This flaw arises from an improper application of the wp_kses_allowed_html function, permitting the inclusion of the 'onclick' attribute in specific HTML elements without adequate restrictions or context verification. As a result, unauthenticated attackers can inject malicious web scripts into the pages, which will execute whenever users navigate to these compromised pages, posing a significant security risk.
Affected Version(s)
Thanh Toán Quét Mã QR Code Tự Động – MoMo, ViettelPay, VNPay và 40 ngân hàng Việt Nam * <= 2.0.1