Stored Cross-Site Scripting Vulnerability in Absolute Reviews Plugin
CVE-2024-8965
5.4MEDIUM
What is CVE-2024-8965?
The Absolute Reviews plugin for WordPress is prone to a Stored Cross-Site Scripting (XSS) vulnerability that arises in the 'Name' field of a custom post criteria. This issue stems from inadequate input sanitization and output escaping practices. As a result, authenticated attackers with Contributor-level access or higher can inject malicious web scripts. The injected scripts can be executed whenever any user accesses the compromised page, potentially leading to unauthorized actions and information theft.
Affected Version(s)
Absolute Reviews * <= 1.1.3