CVE-2024-12579
Last modified
CVE-2024-12579 is a medium-severity vulnerability rated 5.3/10 on the CVSS scale. The Minify HTML plugin for WordPress is vulnerable to Regular Expression Denial of Service (ReDoS) in all versions up to, and including, 2.1.10. This is due to processing user-supplied input as a regular expression. EPSS estimates a 0.33% chance of exploitation in the next 30 days.
Description
The Minify HTML plugin for WordPress is vulnerable to Regular Expression Denial of Service (ReDoS) in all versions up to, and including, 2.1.10. This is due to processing user-supplied input as a regular expression. This makes it possible for unauthenticated attackers to create comments that can cause catastrophic backtracking and break pages.
Metrics
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
Weakness Enumeration
References
Timeline
- Published
- Last Modified
- Status
- Deferred
Frequently Asked Questions
What is CVE-2024-12579?
How severe is CVE-2024-12579?
How do I fix CVE-2024-12579?
Are you affected by CVE-2024-12579?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
