Lucene search

K
vulnrichmentWPScanVULNRICHMENT:CVE-2024-4477
HistoryJun 21, 2024 - 6:00 a.m.

CVE-2024-4477 WP Logs Book <= 1.0.1 - Unauthenticated Stored XSS

2024-06-2106:00:04
WPScan
github.com
2
cve-2024-4477
wordpress plugin
unauthenticated stored xss
admin dashboard

AI Score

6

Confidence

High

SSVC

Exploitation

poc

Automatable

no

Technical Impact

partial

The WP Logs Book WordPress plugin through 1.0.1 does not sanitise and escape some of its log data before outputting them back in an admin dashboard, leading to an Unauthenticated Stored Cross-Site Scripting

ADP Affected

[
  {
    "cpes": [
      "cpe:2.3:a:onetarek:wp-logs-book:*:*:*:*:*:*:*:*"
    ],
    "vendor": "onetarek",
    "product": "wp-logs-book",
    "versions": [
      {
        "status": "affected",
        "version": "0",
        "versionType": "semver",
        "lessThanOrEqual": "1.0.1"
      }
    ],
    "defaultStatus": "unaffected"
  }
]

AI Score

6

Confidence

High

SSVC

Exploitation

poc

Automatable

no

Technical Impact

partial

Related for VULNRICHMENT:CVE-2024-4477