Unauthenticated Attackers Can Inject Arbitrary Web Scripts Via Reflected Cross-Site Scripting in WordPress's Terms Descriptions Plugin
CVE-2024-9374
What is CVE-2024-9374?
The Terms descriptions plugin for WordPress is susceptible to reflected cross-site scripting (XSS) vulnerabilities. This stems from the improper handling of user input via the add_query_arg function that lacks adequate escaping in the URL. As a consequence, unauthenticated attackers can exploit this vulnerability to inject arbitrary web scripts into affected pages. These scripts can execute when a user is misled into clicking a malicious link, posing significant risks to user data and website integrity. It is crucial for site administrators to carefully assess and update their plugins to mitigate potential exploit attempts.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
Terms descriptions * <= 3.4.6
References
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved