Stored Cross-Site Scripting Vulnerability in PeepSo Core Groups Plugin by PeepSo
CVE-2024-9017
7.2HIGH
What is CVE-2024-9017?
The PeepSo Core: Groups plugin for WordPress presents a stored cross-site scripting vulnerability through inadequate input sanitization and output escaping in the Group Description field. This flaw allows authenticated users with Subscriber-level access or higher to embed arbitrary scripts into web pages. Such scripts are executed whenever users navigate to the compromised pages, potentially leading to unauthorized information disclosure or manipulation within the affected WordPress sites.
Affected Version(s)
PeepSo Core: Groups * <= 6.4.6.0