Lucene search

K
cve[email protected]CVE-2024-3076
HistoryApr 26, 2024 - 2:15 p.m.

CVE-2024-3076

2024-04-2614:15:07
web.nvd.nist.gov
33
cve-2024-3076
mm-email2image
wordpress
csrf
sanitisation
escaping
stored xss payloads
nvd

8.7 High

AI Score

Confidence

High

0.0004 Low

EPSS

Percentile

9.0%

The MM-email2image WordPress plugin through 0.2.5 does not have CSRF check in some places, and is missing sanitisation as well as escaping, which could allow attackers to make logged in admin add Stored XSS payloads via a CSRF attack

Affected configurations

Vulners
Node
beldentofino_argon_fa-tsa-220-mm\/mmRange0.2.5
VendorProductVersionCPE
beldentofino_argon_fa\-tsa\-220\-mm\/mm*cpe:2.3:h:belden:tofino_argon_fa\-tsa\-220\-mm\/mm:*:*:*:*:*:*:*:*

CNA Affected

[
  {
    "vendor": "Unknown",
    "product": "MM-email2image",
    "versions": [
      {
        "status": "affected",
        "versionType": "semver",
        "version": "0",
        "lessThanOrEqual": "0.2.5"
      }
    ],
    "defaultStatus": "affected"
  }
]

8.7 High

AI Score

Confidence

High

0.0004 Low

EPSS

Percentile

9.0%