CVE-2024-4041
MEDIUMYoast SEO <= 22.5 - Unauthenticated Reflected Cross-Site Scripting via URL Parameter
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2024-4041. PoCs published by RandomRobbieBF.
AI-analyzed exploit summary The repository provides a functional proof-of-concept for CVE-2024-4041, demonstrating a reflected XSS vulnerability in Yoast SEO plugin for WordPress. The PoC involves crafting a malicious URL that, when interacted with, executes arbitrary JavaScript in the context of the victim's browser.
Description
The Yoast SEO plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via URLs in all versions up to, and including, 22.5 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a link.
Exploits (1)
The repository provides a functional proof-of-concept for CVE-2024-4041, demonstrating a reflected XSS vulnerability in Yoast SEO plugin for WordPress. The PoC involves crafting a malicious URL that, when interacted with, executes arbitrary JavaScript in the context of the victim's browser.
References (6)
Scores
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N