CVE-2024-3231
Popup4Phone <= 1.3.2 - Unauthenticated Stored XSS
Record summary
CVE-2024-3231 has a selected CVSS score of 6.1 (medium); EIP currently links 1 Nuclei template.
Description
The Popup4Phone WordPress plugin through 1.3.2 does not sanitise and escape some parameters, which could allow unauthenticated users to perform Cross-Site Scripting attacks against admins.
Exploitation context
Available material
- Nuclei templates
- 1
CISA SSVC decision
CISA Coordinator · SSVC 2.0.3 · Evaluated May 17, 2024 · Source: CVE List
Affected products and versions
1| Product | Source | Version range | Status |
|---|---|---|---|
Popup4PhoneDefault status: affected | CVE List | Through 1.3.2 | affected |
Nuclei templates
1ProjectDiscoveryMEDIUMPopup4Phone <= 1.3.2 - Unauthenticated Stored Cross-Site ScriptingCVSS 6.1
Popup4Phone WordPress plugin through 1.3.2 contains a reflected cross-site scripting caused by unsanitized parameters, letting unauthenticated users execute scripts in admin browsers, exploit requires sending crafted requests.
Impact
Attackers can execute scripts in admin browsers, potentially leading to session hijacking or defacement.
Remediation
Update to the latest version of Popup4Phone plugin.
Source: ProjectDiscovery