Lucene search

K
nvd[email protected]NVD:CVE-2024-3076
HistoryApr 26, 2024 - 2:15 p.m.

CVE-2024-3076

2024-04-2614:15:07
web.nvd.nist.gov
1
cve-2024-3076
csrf
sanitisation
escaping
stored xss
wordpress plugin
security vulnerability

5.6 Medium

AI Score

Confidence

High

0.0004 Low

EPSS

Percentile

9.2%

The MM-email2image WordPress plugin through 0.2.5 does not have CSRF check in some places, and is missing sanitisation as well as escaping, which could allow attackers to make logged in admin add Stored XSS payloads via a CSRF attack

5.6 Medium

AI Score

Confidence

High

0.0004 Low

EPSS

Percentile

9.2%

Related for NVD:CVE-2024-3076