Unauthenticated Attackers Can Trick Users into Injecting Arbitrary Web Scripts
CVE-2024-9371
Key Information:
- Vendor
Wordpress
- Vendor
- CVE Published:
- 21 November 2024
What is CVE-2024-9371?
The Branda β White Label & Branding, Custom Login Page Customizer plugin for WordPress exhibits a vulnerability that allows for Reflected Cross-Site Scripting. This issue arises from improper handling of the URL via the remove_query_arg function, lacking necessary escaping in all versions through 3.4.19. As a result, unauthenticated attackers can craft malicious links that, when clicked by unsuspecting users, execute arbitrary web scripts within their browsers. This presents a significant risk as it can lead to unauthorized actions or data exposure on affected sites.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
Branda β Branda β White Label & Branding, Custom Login Page Customizer * <= 3.4.21
References
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved