Stored Cross-Site Scripting Vulnerability in PeepSo Core Groups Plugin by PeepSo
CVE-2024-9017

7.2HIGH

Key Information:

Vendor

WordPress

Vendor
CVE Published:
3 July 2025

What is CVE-2024-9017?

The PeepSo Core: Groups plugin for WordPress presents a stored cross-site scripting vulnerability through inadequate input sanitization and output escaping in the Group Description field. This flaw allows authenticated users with Subscriber-level access or higher to embed arbitrary scripts into web pages. Such scripts are executed whenever users navigate to the compromised pages, potentially leading to unauthorized information disclosure or manipulation within the affected WordPress sites.

Affected Version(s)

PeepSo Core: Groups * <= 6.4.6.0

References

CVSS V3.1

Score:
7.2
Severity:
HIGH
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Bikram Kharal
.