CVE-2024-9115
CVSS 3.1 Score 5.4 of 10 (medium)
Details
Summary
CVE-2024-9115 is a newly identified vulnerability affecting the Common Tools for Site plugin for WordPress. This issue allows authenticated attackers with Author-level access and above to execute arbitrary web scripts via Stored Cross-Site Scripting, specifically through SVG file uploads. The flaw stems from insufficient input sanitization and output escaping in all versions up to and including 1.0.2. Successful exploitation can result in unintended code execution whenever a user accesses the infected SVG file, potentially leading to serious security implications. It is strongly recommended that WordPress users update the plugin to the latest version to mitigate this risk.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.
Affected Vendors
- WordPress