Record summary

CVE-2024-37261 has a selected CVSS score of 7.1 (high); EIP currently links 1 Nuclei template.

Description

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WP Lab WP-Lister Lite for Amazon wp-lister-for-amazon.This issue affects WP-Lister Lite for Amazon: from n/a through <= 2.6.16.

Description source: CVE List

Exploitation context

Known exploitation

VulnCheck KEV
Listed · Jun 27, 2024 · VulnCheck
Reported exploitation
Observed · VulnCheck

Available material

Nuclei templates
1

CISA SSVC decision

ExploitationPoC
AutomatableNo
Technical impactPartial

CISA Coordinator · SSVC 2.0.3 · Evaluated Jul 22, 2024 · Source: CVE List

Affected products and versions

2
ProductSourceVersion rangeStatus

WP-Lister Lite for Amazon

Browse WP Lab / WP-Lister Lite for Amazonwp-lister-for-amazon

Default status: unaffected

CVE ListThrough 2.6.16affected

Default status: unknown

VulnCheck, CVE ListThrough 2.6.16affected
2.6.17*unaffected

Nuclei templates

1
ProjectDiscoveryMEDIUMWP-Lister Lite for Amazon <= 2.6.16 - Cross-Site ScriptingCVSS 6.1

The WP-Lister Lite for Amazon plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and including, 2.6.16 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a link.

WeaknessesCWE-79
AuthorsKazgangap
Template tagscvecve2024wordpresswpwp-pluginwp-lister-for-amazonxssvkevauthenticated
CVSS vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N

Source: ProjectDiscovery

References

3