Record summary

CVE-2024-37259 has a selected CVSS score of 7.1 (high); EIP currently links 1 Nuclei template.

Description

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WP Extended The Ultimate WordPress Toolkit – WP Extended wpextended.This issue affects The Ultimate WordPress Toolkit – WP Extended: from n/a through <= 2.4.7.

Description source: CVE List

Exploitation context

Known exploitation

VulnCheck KEV
Listed · Jun 27, 2024 · VulnCheck
Reported exploitation
Observed · VulnCheck

Available material

Nuclei templates
1

CISA SSVC decision

ExploitationNone
AutomatableNo
Technical impactPartial

CISA Coordinator · SSVC 2.0.3 · Evaluated Jul 22, 2024 · Source: CVE List

Affected products and versions

2
ProductSourceVersion rangeStatus

The Ultimate WordPress Toolkit – WP Extended

Browse WP Extended / The Ultimate WordPress Toolkit – WP Extendedwpextended

Default status: unaffected

CVE ListThrough 2.4.7affected
VulnCheckVersion data not supplied

Nuclei templates

1
ProjectDiscoveryMEDIUMWP Extended < 3.0.0 - Stored Cross-Site ScriptingCVSS 6.1

The Ultimate WordPress Toolkit - WP Extended plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 2.4.7 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

Impact

Attackers can execute malicious scripts in users' browsers, potentially stealing cookies, session tokens, or performing actions true behalf of users.

Remediation

Update to WP Extended 3.0.0 or later.

WeaknessesCWE-79
Authors0xanis
Template tagscvecve2024wordpresswp-scanwp-pluginwpextendedxssvkev
CVSS vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N

Source: ProjectDiscovery

References

3