Stored Cross-Site Scripting Vulnerability in Absolute Reviews Plugin
CVE-2024-8965

5.4MEDIUM

Key Information:

Vendor
Wordpress
Vendor
CVE Published:
27 September 2024

Summary

The Absolute Reviews plugin for WordPress is prone to a Stored Cross-Site Scripting (XSS) vulnerability that arises in the 'Name' field of a custom post criteria. This issue stems from inadequate input sanitization and output escaping practices. As a result, authenticated attackers with Contributor-level access or higher can inject malicious web scripts. The injected scripts can be executed whenever any user accesses the compromised page, potentially leading to unauthorized actions and information theft.

Affected Version(s)

Absolute Reviews * <= 1.1.3

References

CVSS V3.1

Score:
5.4
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Muhammad Adel
.