Lucene search

K
cveWPScanCVE-2024-5728
HistoryJun 28, 2024 - 6:15 a.m.

CVE-2024-5728

2024-06-2806:15:06
WPScan
web.nvd.nist.gov
27
cve-2024-5728
animated al list
wordpress plugin
cross-site scripting
reflected
high privilege users

CVSS3

5.4

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

REQUIRED

Scope

UNCHANGED

Confidentiality Impact

LOW

Integrity Impact

LOW

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N

AI Score

5.8

Confidence

High

EPSS

0

Percentile

9.1%

The Animated AL List WordPress plugin through 1.0.6 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin

Affected configurations

Vulners
Vulnrichment
Node
eralionanimated_countersRange1.0.6wordpress
VendorProductVersionCPE
eralionanimated_counters*cpe:2.3:a:eralion:animated_counters:*:*:*:*:*:wordpress:*:*

CNA Affected

[
  {
    "vendor": "Unknown",
    "product": "Animated AL List",
    "versions": [
      {
        "status": "affected",
        "versionType": "semver",
        "version": "0",
        "lessThanOrEqual": "1.0.6"
      }
    ],
    "defaultStatus": "affected"
  }
]

CVSS3

5.4

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

REQUIRED

Scope

UNCHANGED

Confidentiality Impact

LOW

Integrity Impact

LOW

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N

AI Score

5.8

Confidence

High

EPSS

0

Percentile

9.1%