CVE-2024-5151
Last modified
CVE-2024-5151 is a high-severity vulnerability rated 7.1/10 on the CVSS scale. The SULly WordPress plugin before 4.3.1 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup). EPSS estimates a 0.39% chance of exploitation in the next 30 days.
Description
The SULly WordPress plugin before 4.3.1 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)
Metrics
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Toolstack | Sully | < 4.3.1 |
References
- https://wpscan.com/vulnerability/1ede4c66-9932-4ba6-bba1-0ba13f5a2f8f/Exploit, Third Party Advisory
- https://wpscan.com/vulnerability/1ede4c66-9932-4ba6-bba1-0ba13f5a2f8f/Exploit, Third Party Advisory
Timeline
- Published
- Last Modified
- Status
- Analyzed
Frequently Asked Questions
What is CVE-2024-5151?
How severe is CVE-2024-5151?
How do I fix CVE-2024-5151?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2024
- CVE-2024-51504When using IPAuthenticationProvider in ZooKeeper Admin Serve…9.1
- CVE-2024-51505An issue was discovered in Atos Eviden IDRA before 2.7.1. A …8
- CVE-2024-51506Tiki through 27.0 allows users who have certain permissions …4.8
- CVE-2024-51507Tiki through 27.0 allows users who have certain permissions …4.8
- CVE-2024-51508Tiki through 27.0 allows users who have certain permissions …4.8
- CVE-2024-51509Tiki through 27.0 allows users who have certain permissions …4.8
- CVE-2024-51510Out-of-bounds access vulnerability in the logo module Impact…5.5
- CVE-2024-51511Vulnerability of parameter type not being verified in the Wa…5.5
- CVE-2024-51512Vulnerability of parameter type not being verified in the Wa…5.5
- CVE-2024-51513Vulnerability of processes not being fully terminated in the…5.5
- CVE-2024-51514Vulnerability of pop-up windows belonging to no app in the V…5.5
- CVE-2024-51515Race condition vulnerability in the kernel network module Im…4.7
Are you affected by CVE-2024-5151?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
