Lucene search

K
vulnrichmentJpcertVULNRICHMENT:CVE-2024-32674
HistoryMay 08, 2024 - 3:37 a.m.

CVE-2024-32674

2024-05-0803:37:49
jpcert
github.com
4
heateor social login
xss
vulnerability
wordpress
cross-site scripting

AI Score

6.2

Confidence

High

EPSS

0

Percentile

9.0%

SSVC

Exploitation

none

Automatable

no

Technical Impact

partial

Heateor Social Login WordPress prior to 1.1.32 contains a cross-site scripting vulnerability. If this vulnerability is exploited, an arbitrary script may be executed on the web browser of the user who accessed the website using the product.

CNA Affected

[
  {
    "vendor": "Heateor",
    "product": "Heateor Social Login WordPress",
    "versions": [
      {
        "version": "prior to 1.1.32",
        "status": "affected"
      }
    ]
  }
]

ADP Affected

[
  {
    "cpes": [
      "cpe:2.3:a:bestwebsoft:social_login:*:*:*:*:*:wordpress:*:*"
    ],
    "vendor": "bestwebsoft",
    "product": "social_login",
    "versions": [
      {
        "status": "affected",
        "version": "0",
        "lessThan": "1.1..32",
        "versionType": "custom"
      }
    ],
    "defaultStatus": "unknown"
  }
]

AI Score

6.2

Confidence

High

EPSS

0

Percentile

9.0%

SSVC

Exploitation

none

Automatable

no

Technical Impact

partial

Related for VULNRICHMENT:CVE-2024-32674