CVE-2024-35694
WordPress WPMobile.App plugin <= 11.41 - Cross Site Scripting (XSS) vulnerability
Record summary
CVE-2024-35694 has a selected CVSS score of 7.1 (high); EIP currently links 1 Nuclei template.
Description
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Amauri WPMobile.App wpappninja.This issue affects WPMobile.App: from n/a through <= 11.41.
Exploitation context
Known exploitation
- VulnCheck KEV
- Listed · Jun 6, 2024 · VulnCheck
- Reported exploitation
- Observed · VulnCheck
Available material
- Nuclei templates
- 1
CISA SSVC decision
CISA Coordinator · SSVC 2.0.3 · Evaluated Jun 10, 2024 · Source: CVE List
Affected products and versions
2| Product | Source | Version range | Status |
|---|---|---|---|
Default status: unaffected | CVE List | Through 11.41 | affected |
wpmobile.appBrowse amauri / wpmobile.app | VulnCheck | Version data not supplied | |
Nuclei templates
1ProjectDiscoveryHIGHWordpress WPMobile.App >= 11.42 - Cross-Site ScriptingCVSS 7.1
WPMobile.App versions up to 11.41 contain a reflected cross-site scripting (XSS) caused by improper input neutralization during web page generation, letting attackers execute scripts in the victim's browser, exploit requires attacker to craft malicious input.
Impact
Attackers can execute arbitrary scripts in the victim's browser, potentially stealing cookies, session tokens, or performing actions on behalf of the user.
Remediation
Implement proper input sanitization and output encoding, and update to the latest version of WPMobile.App.
Source: ProjectDiscovery