CVE-2024-9653

CVSS 3.1 Score 6.1 of 10 (medium)

Details

Published Nov 20, 2024
Updated: Nov 26, 2024
CWE ID 79

Summary

CVE-2024-9653 is a Reflected Cross-Site Scripting (XSS) vulnerability affecting the Table Reservation plugin of the Restaurant Menu – Food Ordering System for WordPress. Versions up to and including 2.4.2 are susceptible to this issue due to insufficient sanitization and output escaping of the 'action' parameter. Unauthenticated attackers can exploit this flaw by injecting arbitrary web scripts and tricking users into performing an action, such as clicking a malicious link, leading to potential security risks and data breaches.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share