CVE-2024-7082

CVSS 3.1 Score 6.1 of 10 (medium)

Details

Published Aug 6, 2024
Updated: Oct 27, 2024
CWE ID 79

Summary

CVE-2024-7082 is a vulnerability affecting the Easy Table of Contents plugin for WordPress. Prior to version 2.0.68, this plugin fails to sanitize and escape certain parameters, creating an opportunity for attackers with Editor-level access to execute Cross-Site Scripting attacks. This can lead to unintended execution of malicious scripts within a user's browser, potentially compromising their account or exposing sensitive information. By exploiting this vulnerability, an attacker could gain elevated privileges or steal sensitive data, making it essential for WordPress users to update their plugins to the latest version as soon as possible.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share