Lucene search

K
cveWordfenceCVE-2024-1348
HistoryMay 02, 2024 - 5:15 p.m.

CVE-2024-1348

2024-05-0217:15:10
Wordfence
web.nvd.nist.gov
34
phlox theme
wordpress
stored xss
input sanitization
output escaping
cve-2024-1348
nvd

CVSS3

6.4

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

CHANGED

Confidentiality Impact

LOW

Integrity Impact

LOW

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N

AI Score

5.8

Confidence

High

EPSS

0

Percentile

14.0%

The Shortcodes and extra features for Phlox theme plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the custom JS parameter in all versions up to, and including, 2.15.5 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor access or higher, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

Affected configurations

Vulners
Vulnrichment
Node
avertashortcodes_and_extra_features_for_phlox_themeRange2.15.5wordpress
VendorProductVersionCPE
avertashortcodes_and_extra_features_for_phlox_theme*cpe:2.3:a:averta:shortcodes_and_extra_features_for_phlox_theme:*:*:*:*:*:wordpress:*:*

CNA Affected

[
  {
    "vendor": "averta",
    "product": "Shortcodes and extra features for Phlox theme",
    "versions": [
      {
        "version": "*",
        "status": "affected",
        "lessThanOrEqual": "2.15.5",
        "versionType": "semver"
      }
    ],
    "defaultStatus": "unaffected"
  }
]

CVSS3

6.4

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

CHANGED

Confidentiality Impact

LOW

Integrity Impact

LOW

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N

AI Score

5.8

Confidence

High

EPSS

0

Percentile

14.0%