Stored Cross-Site Scripting Vulnerability Affects Authenticated Users
CVE-2024-9452
5.4MEDIUM
What is CVE-2024-9452?
The Branding plugin for WordPress suffers from a Stored Cross-Site Scripting vulnerability attributed to inadequate input sanitization and output escaping mechanisms. This vulnerability affects all versions up to and including 1.0, enabling authenticated attackers with Author-level access or higher to upload malicious SVG files. Once these files are accessed by users, the injected web scripts execute, potentially compromising user data and application security.
Affected Version(s)
Branding * <= 1.0