3.5

CVE-2024-10515

Exploit

SEO Plugin by Squirrly SEO < 12.3.21 - Editor+ Stored XSS

SEO Plugin by Squirrly SEO <= 12.3.20 - Authenticated (Editor+) Stored Cross-Site Scripting

In the process of testing the SEO Plugin by Squirrly SEO WordPress plugin before 12.3.21, a vulnerability was found that allows you to implement Stored XSS on behalf of the editor by embedding malicious script, which entails account takeover backdoor
Mögliche Gegenmaßnahme
GEO Plugin by Squirrly SEO: Update to version 12.3.21, or a newer patched version
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
SquirrlySeo Plugin By Squirrly Seo SwPlatformwordpress Version < 12.3.21
VulnDex Vulnerability Enrichment
Diese Information steht angemeldeten Benutzern zur Verfügung. Login Login
Weitere Schwachstelleninformationen
SystemWordPress Plugin
Produkt GEO Plugin by Squirrly SEO
Version *-12.3.20
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.3% 0.218
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
134c704f-9b21-4f2e-91b3-4a467353bcc0 3.5 0.9 2.5
CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:U/C:L/I:L/A:N
CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.

https://wpscan.com/vulnerability/367aad17-fbb5-48eb-8829-5d3513098d02/
Third Party Advisory
Exploit
https://www.wordfence.com/threat-intel/vulnerabilities/id/f15ad88b-7dcb-4a36-877a-e7017d98d498
Third Party Advisory