CVE-2024-4061
Last modified
CVE-2024-4061 is a medium-severity vulnerability rated 4.8/10 on the CVSS scale. The Survey Maker WordPress plugin before 4.2.9 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup). EPSS estimates a 0.42% chance of exploitation in the next 30 days.
Description
The Survey Maker WordPress plugin before 4.2.9 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)
Metrics
CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Ays-Pro | Survey Maker | < 4.2.9 |
References
- https://wpscan.com/vulnerability/175a9f3a-1f8d-44d1-8a12-e037251b025d/Exploit, Third Party Advisory
- https://wpscan.com/vulnerability/175a9f3a-1f8d-44d1-8a12-e037251b025d/Exploit, Third Party Advisory
Timeline
- Published
- Last Modified
- Status
- Analyzed
Frequently Asked Questions
What is CVE-2024-4061?
How severe is CVE-2024-4061?
How do I fix CVE-2024-4061?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2024
- CVE-2024-40600An issue was discovered in the Metrolook skin for MediaWiki …4.8
- CVE-2024-40601An issue was discovered in the MediaWikiChat extension for M…6.5
- CVE-2024-40602An issue was discovered in the Tempo skin for MediaWiki thro…4.8
- CVE-2024-40603An issue was discovered in the ArticleRatings extension for …4.3
- CVE-2024-40604An issue was discovered in the Nimbus skin for MediaWiki thr…4.8
- CVE-2024-40605An issue was discovered in the Foreground skin for MediaWiki…4.8
- CVE-2024-40614EGroupware before 23.1.20240624 mishandles an ORDER BY claus…9.8
- CVE-2024-40616Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultID…
- CVE-2024-40617Path traversal vulnerability exists in FUJITSU Network Edgio…6.5
- CVE-2024-40618Whale browser before 3.26.244.21 allows an attacker to execu…9.6
- CVE-2024-40619CVE-2024-40619 IMPACT A denial-of-service vulnerability exi…7.5
- CVE-2024-4062A vulnerability was found in Hualai Xiaofang iSC5 3.2.2_112 …3.7
Are you affected by CVE-2024-4061?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
