Stored Cross-Site Scripting Vulnerability in PeepSo Core Groups Plugin by PeepSo
CVE-2024-9017
7.2HIGH
What is CVE-2024-9017?
The PeepSo Core: Groups plugin for WordPress presents a stored cross-site scripting vulnerability through inadequate input sanitization and output escaping in the Group Description field. This flaw allows authenticated users with Subscriber-level access or higher to embed arbitrary scripts into web pages. Such scripts are executed whenever users navigate to the compromised pages, potentially leading to unauthorized information disclosure or manipulation within the affected WordPress sites.
Affected Version(s)
PeepSo Core: Groups * <= 6.4.6.0
References
CVSS V3.1
Score:
7.2
Severity:
HIGH
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Changed
Timeline
Vulnerability published
Vulnerability Reserved
Credit
Bikram Kharal