CVE-2024-3282
Last modified
CVE-2024-3282 is a medium-severity vulnerability rated 4.8/10 on the CVSS scale. The WP Table Builder WordPress plugin through 1.5.0 does not sanitise and escape some of its Table data, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup). EPSS estimates a 0.29% chance of exploitation in the next 30 days.
Description
The WP Table Builder WordPress plugin through 1.5.0 does not sanitise and escape some of its Table data, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)
Metrics
CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Wptablebuilder | Wp Table Builder | < 1.5.0 |
References
- https://wpscan.com/vulnerability/12bf5e8e-24c9-48b9-b94c-c14ed60d7c15/Exploit, Third Party Advisory
Timeline
- Published
- Last Modified
- Status
- Analyzed
Frequently Asked Questions
What is CVE-2024-3282?
How severe is CVE-2024-3282?
How do I fix CVE-2024-3282?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2024
- CVE-2024-32814Missing Authorization vulnerability in Zorem Advanced Local …5.3
- CVE-2024-32815Improper Neutralization of Input During Web Page Generation …5.9
- CVE-2024-32816Exposure of Sensitive Information to an Unauthorized Actor v…7.5
- CVE-2024-32817Deserialization of Untrusted Data vulnerability in Javier Ca…4.4
- CVE-2024-32818Missing Authorization vulnerability in realmag777 WordPress …8.8
- CVE-2024-32819Server-Side Request Forgery (SSRF) vulnerability in Culqi.Th…4.9
- CVE-2024-32820Missing Authorization vulnerability in Social Share Pro Soci…5.3
- CVE-2024-32821Missing Authorization vulnerability in TotalSuite Total Poll…4.3
- CVE-2024-32822Missing Authorization vulnerability in impleCode Reviews Plu…4.3
- CVE-2024-32823Authorization Bypass Through User-Controlled Key vulnerabili…5.3
- CVE-2024-32824Missing Authorization vulnerability in Evergreen Content Pos…8.8
- CVE-2024-32825Insertion of Sensitive Information Into Sent Data vulnerabil…7.5
Are you affected by CVE-2024-3282?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
