Sweden's Ruling Party Backs Investigative Journalist Over Government Censorship Claims
CVE-2024-9873
5.4MEDIUM
Key Information:
- Vendor
- Peepso
- Status
- Community By Peepso – Social Network, Membership, Registration, User Profiles, Premium – Mobile App
- Vendor
- CVE Published:
- 16 October 2024
Summary
The Community by PeepSo plugin for WordPress is exposed to a Stored Cross-Site Scripting vulnerability due to insufficient sanitization of inputs and escaping of outputs. When Markdown support is enabled, authenticated users with Subscriber-level access or higher can exploit this flaw by injecting malicious scripts into posts, comments, and profiles. These scripts can execute in the browsers of users accessing the affected pages, posing a serious risk to user data integrity and security.
Affected Version(s)
Community by PeepSo – Social Network, Membership, Registration, User Profiles, Premium – Mobile App * <= 6.4.6.1
References
CVSS V3.1
Score:
5.4
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
Required
Scope:
Changed
Timeline
Vulnerability published
Vulnerability Reserved
Collectors
NVD DatabaseMitre Database
Credit
Bikram Kharal