CVE-2024-39646
WordPress Custom 404 Pro plugin <= 3.11.1 - Reflected Cross Site Scripting (XSS) vulnerability
Record summary
CVE-2024-39646 has a selected CVSS score of 7.1 (high); EIP currently links 1 Nuclei template.
Description
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Kunal Custom 404 Pro custom-404-pro.This issue affects Custom 404 Pro: from n/a through <= 3.11.1.
Exploitation context
Known exploitation
- VulnCheck KEV
- Listed · Aug 1, 2024 · VulnCheck
- Reported exploitation
- Observed · VulnCheck
Available material
- Nuclei templates
- 1
CISA SSVC decision
CISA Coordinator · SSVC 2.0.3 · Evaluated Aug 2, 2024 · Source: CVE List
Affected products and versions
2| Product | Source | Version range | Status |
|---|---|---|---|
Custom 404 ProBrowse Kunal / Custom 404 ProDefault status: unaffected | CVE List | Through 3.11.1 | affected |
custom_404_proBrowse kunalnagar / custom_404_pro | VulnCheck | Version data not supplied | |
Nuclei templates
1ProjectDiscoveryHIGHWordPress Custom 404 Pro <= 3.11.1 - Reflected XSSCVSS 7.1
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Kunal Nagar Custom 404 Pro allows Reflected XSS.This issue affects Custom 404 Pro: from n/a through 3.11.1.
Impact
Attackers can execute arbitrary scripts in victims' browsers, leading to session hijacking, defacement, or redirection.
Remediation
Update to version 3.11.2 or later.
Source: ProjectDiscovery