CVE-2024-3058
Last modified
CVE-2024-3058 is a medium-severity vulnerability rated 5.4/10 on the CVSS scale. The ENL Newsletter WordPress plugin through 1.0.1 does not have CSRF check in some places, and is missing sanitisation as well as escaping, which could allow attackers to make logged in admin add Stored XSS payloads via a CSRF attack. EPSS estimates a 0.21% chance of exploitation in the next 30 days.
Description
The ENL Newsletter WordPress plugin through 1.0.1 does not have CSRF check in some places, and is missing sanitisation as well as escaping, which could allow attackers to make logged in admin add Stored XSS payloads via a CSRF attack
Metrics
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Enl Newsletter Plugin Project | Enl-Newsletter | <= 1.0.1 |
References
- https://wpscan.com/vulnerability/fc33c79d-ad24-4d55-973a-25280995a2ab/Exploit, Third Party Advisory
- https://wpscan.com/vulnerability/fc33c79d-ad24-4d55-973a-25280995a2ab/Exploit, Third Party Advisory
Timeline
- Published
- Last Modified
- Status
- Analyzed
Frequently Asked Questions
What is CVE-2024-3058?
How severe is CVE-2024-3058?
How do I fix CVE-2024-3058?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2024
- CVE-2024-30568Netgear R6850 1.1.0.88 was discovered to contain a command i…9.8
- CVE-2024-30569An information leak in currentsetting.htm of Netgear R6850 v…7.5
- CVE-2024-3057A flaw exists whereby a user can make a specific call to a F…9.8
- CVE-2024-30570An information leak in debuginfo.htm of Netgear R6850 v1.1.0…5.3
- CVE-2024-30571An information leak in the BRS_top.html component of Netgear…7.5
- CVE-2024-30572Netgear R6850 1.1.0.88 was discovered to contain a command i…8
- CVE-2024-30583Tenda FH1202 v1.2.0.14(408) has a stack overflow vulnerabili…8
- CVE-2024-30584Tenda FH1202 v1.2.0.14(408) has a stack overflow vulnerabili…9.8
- CVE-2024-30585Tenda FH1202 v1.2.0.14(408) has a stack overflow vulnerabili…6.5
- CVE-2024-30586Tenda FH1202 v1.2.0.14(408) has a stack overflow vulnerabili…6.5
- CVE-2024-30587Tenda FH1202 v1.2.0.14(408) has a stack overflow vulnerabili…9.8
- CVE-2024-30588Tenda FH1202 v1.2.0.14(408) has a stack overflow vulnerabili…4.3
Are you affected by CVE-2024-3058?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
