Unauthenticated Attackers Can Inject Arbitrary Web Scripts Through Reflected Cross-Site Scripting in 10Web Social Post Feed Plugin
CVE-2024-9607

6.1MEDIUM

Key Information:

Vendor
Wordpress
Vendor
CVE Published:
25 October 2024

Summary

The 10Web Social Post Feed plugin for WordPress is susceptible to Reflected Cross-Site Scripting due to improper handling of query parameters via the add_query_arg function. This vulnerability affects all versions up to and including 1.2.9. Unauthenticated attackers could exploit this flaw by crafting malicious links that, when clicked by users, execute arbitrary scripts within their web browsers. This exploit can occur specifically when the 'leave a review' notification is displayed on the webpage, creating an opportunity for attackers to manipulate user actions.

Affected Version(s)

10Web Social Post Feed * <= 1.2.9

References

CVSS V3.1

Score:
6.1
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Dale Mavers
.