CVE-2024-29137
WordPress Tourfic plugin <= 2.11.7 - Reflected Cross Site Scripting (XSS) vulnerability
Record summary
CVE-2024-29137 has a selected CVSS score of 7.1 (high); EIP currently links 1 Nuclei template.
Description
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Themefic Tourfic tourfic.This issue affects Tourfic: from n/a through <= 2.11.7.
Exploitation context
Known exploitation
- VulnCheck KEV
- Listed · Mar 18, 2024 · VulnCheck
- Reported exploitation
- Observed · VulnCheck
Available material
- Nuclei templates
- 1
CISA SSVC decision
CISA Coordinator · SSVC 2.0.3 · Evaluated Mar 19, 2024 · Source: CVE List
Affected products and versions
2| Product | Source | Version range | Status |
|---|---|---|---|
TourficBrowse Themefic / TourficDefault status: unaffected | CVE List | Through 2.11.7 | affected |
tourficBrowse themefic / tourfic | VulnCheck | Version data not supplied | |
Nuclei templates
1ProjectDiscoveryHIGHWordPress Tourfic Plugin <= 2.11.7 - Cross-Site ScriptingCVSS 7.1
The Tourfic plugin for WordPress is vulnerable to Reflected Cross-Site Scripting (XSS) in versions up to and including 2.11.7 due to insufficient input sanitization and output escaping in the 'place' parameter.
Impact
Attackers can execute malicious scripts in users' browsers, potentially stealing cookies, session tokens, or performing actions on behalf of users.
Remediation
Update to Tourfic version 2.11.8 or later.
Source: ProjectDiscovery