CVE-2024-31108

CVSS 3.1 Score 6.5 of 10 (medium)

Details

Published Mar 31, 2024
Updated: Apr 1, 2024
CWE ID 79

Summary

CVE-2024-31108 is a Cross-site Scripting (XSS) vulnerability affecting the iFlyChat – WordPress Chat plugin. The flaw, named Stored XSS, allows attackers to inject malicious scripts into a chat room's webpage, which can then be executed when other users view the chat. This issue impacts versions of iFlyChat – WordPress Chat from n/a to 4.7.2. Successful exploitation can result in unauthorized access to user data or session hijacking. Users are advised to update the plugin as soon as possible to mitigate this risk.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share