CVE-2024-9115

CVSS 3.1 Score 5.4 of 10 (medium)

Details

Published Sep 26, 2024
Updated: Oct 1, 2024
CWE ID 79

Summary

CVE-2024-9115 is a newly identified vulnerability affecting the Common Tools for Site plugin for WordPress. This issue allows authenticated attackers with Author-level access and above to execute arbitrary web scripts via Stored Cross-Site Scripting, specifically through SVG file uploads. The flaw stems from insufficient input sanitization and output escaping in all versions up to and including 1.0.2. Successful exploitation can result in unintended code execution whenever a user accesses the infected SVG file, potentially leading to serious security implications. It is strongly recommended that WordPress users update the plugin to the latest version to mitigate this risk.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share