CVE-2024-3587

CVSS 3.1 Score 6.4 of 10 (medium)

Details

Published Jul 16, 2024

Summary

CVE-2024-3587 is a vulnerability affecting the Premium Portfolio Features for Phlox theme plugin for WordPress. The vulnerability exists in all versions up to and including 2.3.2 and is categorized as a Stored Cross-Site Scripting (XSS) vulnerability. This vulnerability allows attackers with contributor-level access or higher to inject arbitrary web scripts into pages, which will be executed when accessed by users. The vulnerability occurs due to insufficient input sanitization and output escaping on user-supplied attributes in the plugin's Grid Portfolios Widget. To remediate this vulnerability, users should update the plugin to a version beyond 2.3.2 where the issue has been fixed. This vulnerability poses a medium-level threat as it could potentially allow attackers to execute malicious code on vulnerable websites, compromising their integrity and potentially impacting user confidentiality.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share