Lucene search

K
vulnrichmentWPScanVULNRICHMENT:CVE-2024-6224
HistoryJul 30, 2024 - 6:00 a.m.

CVE-2024-6224 Send email only on Reply to My Comment <= 1.0.6 - Stored XSS via CSRF

2024-07-3006:00:10
WPScan
github.com
5
cve-2024-6224
wordpress
stored xss
csrf
admin
vulnerability

AI Score

5.9

Confidence

High

SSVC

Exploitation

none

Automatable

no

Technical Impact

partial

The Send email only on Reply to My Comment WordPress plugin through 1.0.6 does not have CSRF check in some places, and is missing sanitisation as well as escaping, which could allow attackers to make logged in admin add Stored XSS payloads via a CSRF attack

ADP Affected

[
  {
    "cpes": [
      "cpe:2.3:a:elance360:send-email-only-on-reply-to-my-comment:*:*:*:*:*:*:*:*"
    ],
    "vendor": "elance360",
    "product": "send-email-only-on-reply-to-my-comment",
    "versions": [
      {
        "status": "affected",
        "version": "0",
        "versionType": "semver",
        "lessThanOrEqual": "1.0.6"
      }
    ],
    "defaultStatus": "unknown"
  }
]

AI Score

5.9

Confidence

High

SSVC

Exploitation

none

Automatable

no

Technical Impact

partial

Related for VULNRICHMENT:CVE-2024-6224