Unauthenticated Attackers Can Inject Arbitrary Web Scripts Via Reflected Cross-Site Scripting in WordPress's Terms Descriptions Plugin
CVE-2024-9374

6.1MEDIUM

Key Information:

Vendor
Wordpress
Vendor
CVE Published:
24 October 2024

Summary

The Terms descriptions plugin for WordPress is susceptible to reflected cross-site scripting (XSS) vulnerabilities. This stems from the improper handling of user input via the add_query_arg function that lacks adequate escaping in the URL. As a consequence, unauthenticated attackers can exploit this vulnerability to inject arbitrary web scripts into affected pages. These scripts can execute when a user is misled into clicking a malicious link, posing significant risks to user data and website integrity. It is crucial for site administrators to carefully assess and update their plugins to mitigate potential exploit attempts.

Affected Version(s)

Terms descriptions * <= 3.4.6

References

CVSS V3.1

Score:
6.1
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Dale Mavers
.