Lucene search

K
cvelistPatchstackCVELIST:CVE-2024-24834
HistoryFeb 08, 2024 - 1:13 p.m.

CVE-2024-24834 WordPress BEAR Plugin <= 1.1.4 is vulnerable to Cross Site Scripting (XSS)

2024-02-0813:13:18
CWE-79
Patchstack
www.cve.org
3
cve-2024-24834
wordpress bear plugin
cross site scripting
vulnerability
pluginus.net
woocommerce

CVSS3

5.9

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

HIGH

User Interaction

REQUIRED

Scope

CHANGED

Confidentiality Impact

LOW

Integrity Impact

LOW

Availability Impact

LOW

CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:L

EPSS

0

Percentile

14.0%

Improper Neutralization of Input During Web Page Generation (‘Cross-site Scripting’) vulnerability in realmag777 BEAR – Bulk Editor and Products Manager Professional for WooCommerce by Pluginus.Net allows Stored XSS.This issue affects BEAR – Bulk Editor and Products Manager Professional for WooCommerce by Pluginus.Net: from n/a through 1.1.4.

CNA Affected

[
  {
    "collectionURL": "https://wordpress.org/plugins",
    "defaultStatus": "unaffected",
    "packageName": "woo-bulk-editor",
    "product": "BEAR – Bulk Editor and Products Manager Professional for WooCommerce by Pluginus.Net",
    "vendor": "realmag777",
    "versions": [
      {
        "changes": [
          {
            "at": "1.1.4.1",
            "status": "unaffected"
          }
        ],
        "lessThanOrEqual": "1.1.4",
        "status": "affected",
        "version": "n/a",
        "versionType": "custom"
      }
    ]
  }
]

CVSS3

5.9

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

HIGH

User Interaction

REQUIRED

Scope

CHANGED

Confidentiality Impact

LOW

Integrity Impact

LOW

Availability Impact

LOW

CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:L

EPSS

0

Percentile

14.0%

Related for CVELIST:CVE-2024-24834