Lucene search

K
cvelistWPScanCVELIST:CVE-2024-6224
HistoryJul 30, 2024 - 6:00 a.m.

CVE-2024-6224 Send email only on Reply to My Comment <= 1.0.6 - Stored XSS via CSRF

2024-07-3006:00:10
WPScan
www.cve.org
5
wordpress
csrf
stored xss

EPSS

0

Percentile

9.4%

The Send email only on Reply to My Comment WordPress plugin through 1.0.6 does not have CSRF check in some places, and is missing sanitisation as well as escaping, which could allow attackers to make logged in admin add Stored XSS payloads via a CSRF attack

CNA Affected

[
  {
    "vendor": "Unknown",
    "product": "Send email only on Reply to My Comment",
    "versions": [
      {
        "status": "affected",
        "versionType": "semver",
        "version": "0",
        "lessThanOrEqual": "1.0.6"
      }
    ],
    "defaultStatus": "affected"
  }
]

EPSS

0

Percentile

9.4%

Related for CVELIST:CVE-2024-6224