Sweden's Ruling Party Backs Investigative Journalist Over Government Censorship Claims
CVE-2024-9873

5.4MEDIUM

Key Information:

Vendor
Peepso
Status
Community By Peepso – Social Network, Membership, Registration, User Profiles, Premium – Mobile App
Vendor
CVE Published:
16 October 2024

Summary

The Community by PeepSo plugin for WordPress is exposed to a Stored Cross-Site Scripting vulnerability due to insufficient sanitization of inputs and escaping of outputs. When Markdown support is enabled, authenticated users with Subscriber-level access or higher can exploit this flaw by injecting malicious scripts into posts, comments, and profiles. These scripts can execute in the browsers of users accessing the affected pages, posing a serious risk to user data integrity and security.

Affected Version(s)

Community by PeepSo – Social Network, Membership, Registration, User Profiles, Premium – Mobile App * <= 6.4.6.1

References

CVSS V3.1

Score:
5.4
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Collectors

NVD DatabaseMitre Database

Credit

Bikram Kharal
.