Record summary

CVE-2024-3822 has a selected CVSS score of 4.8 (medium); EIP currently links 1 Nuclei template.

Description

The Base64 Encoder/Decoder WordPress plugin through 0.9.2 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin

Description source: CVE List

Exploitation context

Available material

Nuclei templates
1

CISA SSVC decision

ExploitationNone
AutomatableNo
Technical impactPartial

CISA Coordinator · SSVC 2.0.3 · Evaluated May 15, 2024 · Source: CVE List

Affected products and versions

1
ProductSourceVersion rangeStatus

Base64 Encoder/Decoder

Default status: affected

CVE ListThrough 0.9.2affected

Nuclei templates

1
ProjectDiscoveryMEDIUMBase64 Encoder/Decoder <= 0.9.2 - Cross-Site ScriptingCVSS 6.5

The Base64 Encoder/Decoder WordPress plugin through 0.9.2 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin.

Impact

Unauthenticated attackers can inject malicious JavaScript to target high-privilege users like administrators, potentially leading to session hijacking, privilege escalation, or administrative account compromise.

Remediation

Upgrade to the latest version of the Base64 Encoder/Decoder plugin that addresses this XSS vulnerability.

WeaknessesCWE-79
Authorsomranisecurity
Template tagscvecve2024wordpresswp-pluginwpxssbase64-encoderdecodervuln
CVSS vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N
FOFA: wp-content/plugins/base64-encoderdecoder/

Source: ProjectDiscovery

References

2