Unauthenticated Attackers Can Inject Arbitrary Web Scripts Via Reflected Cross-Site Scripting in WordPress's Terms Descriptions Plugin
CVE-2024-9374
6.1MEDIUM
Summary
The Terms descriptions plugin for WordPress is susceptible to reflected cross-site scripting (XSS) vulnerabilities. This stems from the improper handling of user input via the add_query_arg function that lacks adequate escaping in the URL. As a consequence, unauthenticated attackers can exploit this vulnerability to inject arbitrary web scripts into affected pages. These scripts can execute when a user is misled into clicking a malicious link, posing significant risks to user data and website integrity. It is crucial for site administrators to carefully assess and update their plugins to mitigate potential exploit attempts.
Affected Version(s)
Terms descriptions * <= 3.4.6
References
CVSS V3.1
Score:
6.1
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Changed
Timeline
Vulnerability published
Vulnerability Reserved
Credit
Dale Mavers