CVE-2024-9231

NVD Published Date: October 22, 2024 at 10:15 AM
NVD Last Modified: October 30, 2024 at 06:56 PM
Download Patch
Vulnerability ID
CVE-2024-9231
Severity
MEDIUM
Severity Score
6.1
Summary
The WP-Members Membership Plugin plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of add_query_arg without appropriate escaping on the URL in all versions up to, and including, 3.4.9.5. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a link.
Exploits
-
Metasploit Payload
-
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
CWE ID
CWE-79

Recent Publish

CVE-2024-9050

KB5044097

KB5044098

CVE-2024-49857

CVE-2023-52917

KB5044099

See More ...

See SecOps Solution
in action

Schedule Demo