CVE-2024-37259
WordPress WP Extended plugin <= 2.4.7 - Cross Site Scripting (XSS) vulnerability
Record summary
CVE-2024-37259 has a selected CVSS score of 7.1 (high); EIP currently links 1 Nuclei template.
Description
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WP Extended The Ultimate WordPress Toolkit – WP Extended wpextended.This issue affects The Ultimate WordPress Toolkit – WP Extended: from n/a through <= 2.4.7.
Exploitation context
Known exploitation
- VulnCheck KEV
- Listed · Jun 27, 2024 · VulnCheck
- Reported exploitation
- Observed · VulnCheck
Available material
- Nuclei templates
- 1
CISA SSVC decision
CISA Coordinator · SSVC 2.0.3 · Evaluated Jul 22, 2024 · Source: CVE List
Affected products and versions
2| Product | Source | Version range | Status |
|---|---|---|---|
The Ultimate WordPress Toolkit – WP ExtendedBrowse WP Extended / The Ultimate WordPress Toolkit – WP ExtendedwpextendedDefault status: unaffected | CVE List | Through 2.4.7 | affected |
wp_extendedBrowse wpextended / wp_extended | VulnCheck | Version data not supplied | |
Nuclei templates
1ProjectDiscoveryMEDIUMWP Extended < 3.0.0 - Stored Cross-Site ScriptingCVSS 6.1
The Ultimate WordPress Toolkit - WP Extended plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 2.4.7 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
Impact
Attackers can execute malicious scripts in users' browsers, potentially stealing cookies, session tokens, or performing actions true behalf of users.
Remediation
Update to WP Extended 3.0.0 or later.
Source: ProjectDiscovery