CVE-2024-1977
CVSS 3.1 Score 4.4 of 10 (medium)
Scope changed
Privileges Required high
Attack Complexity high
Confidentiality low
Integrity low
Availability none
Details
Published Feb 29, 2024
Summary
CVE-2024-1977: The Restaurant Solutions Checklist plugin for WordPress, version 1.0.0, is vulnerable to Stored Cross-Site Scripting (XSS) attacks. Authenticated attackers with administrator-level access can exploit this weakness by injecting malicious scripts into Checklist points. These scripts will execute whenever a user accesses an affected page, leading to potential data theft or website defacement. This vulnerability only affects multi-site installations and installations where unfiltered_html has been disabled.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.