Record summary

CVE-2024-3231 has a selected CVSS score of 6.1 (medium); EIP currently links 1 Nuclei template.

Description

The Popup4Phone WordPress plugin through 1.3.2 does not sanitise and escape some parameters, which could allow unauthenticated users to perform Cross-Site Scripting attacks against admins.

Description source: CVE List

Exploitation context

Available material

Nuclei templates
1

CISA SSVC decision

ExploitationNone
AutomatableNo
Technical impactPartial

CISA Coordinator · SSVC 2.0.3 · Evaluated May 17, 2024 · Source: CVE List

Affected products and versions

1
ProductSourceVersion rangeStatus

Popup4Phone

Default status: affected

CVE ListThrough 1.3.2affected

Nuclei templates

1
ProjectDiscoveryMEDIUMPopup4Phone <= 1.3.2 - Unauthenticated Stored Cross-Site ScriptingCVSS 6.1

Popup4Phone WordPress plugin through 1.3.2 contains a reflected cross-site scripting caused by unsanitized parameters, letting unauthenticated users execute scripts in admin browsers, exploit requires sending crafted requests.

Impact

Attackers can execute scripts in admin browsers, potentially leading to session hijacking or defacement.

Remediation

Update to the latest version of Popup4Phone plugin.

WeaknessesCWE-79
AuthorsShivam Kamboj
Template tagscvecve2024wordpresswpscanwp-pluginpopup4phonexssstored
CVSS vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
CPE: cpe:2.3:a:ivanweb:popup4phone:*:*:*:*:*:wordpress:*:*
Shodan: http.component:"WordPress"
FOFA: body="popup4phone"

Source: ProjectDiscovery

References

2