CVE-2024-34568
MEDIUMThemeqx LetterPress <= 1.2.1 - Stored Cross-Site Scripting
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2024-34568. PoCs published by sanupl.
AI-analyzed exploit summary This repository provides a functional proof-of-concept for CVE-2024-34568, demonstrating a stored XSS vulnerability in the LetterPress WordPress plugin (version <= 1.2.1) that allows cookie theft via malicious JavaScript injection in campaign messages.
Description
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Themeqx LetterPress allows Stored XSS.This issue affects LetterPress: from n/a through 1.2.1.
Exploits (1)
This repository provides a functional proof-of-concept for CVE-2024-34568, demonstrating a stored XSS vulnerability in the LetterPress WordPress plugin (version <= 1.2.1) that allows cookie theft via malicious JavaScript injection in campaign messages.
References (1)
Scores
CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:L