CVE-2024-5647
Last modified
CVE-2024-5647 is a medium-severity vulnerability rated 6.4/10 on the CVSS scale. Multiple plugins for WordPress are vulnerable to Stored Cross-Site Scripting via the plugin's bundled Magnific Popups library (version 1.1.0) in various versions due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. EPSS estimates a 0.29% chance of exploitation in the next 30 days.
Description
Multiple plugins for WordPress are vulnerable to Stored Cross-Site Scripting via the plugin's bundled Magnific Popups library (version 1.1.0) in various versions due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. NOTE: This vulnerability was fixed in the upstream library (Magnific Popups version 1.2.0) by disabling the loading of HTML within certain fields by default.
Metrics
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N
Weakness Enumeration
References
Timeline
- Published
- Last Modified
- Status
- Deferred
Frequently Asked Questions
What is CVE-2024-5647?
How severe is CVE-2024-5647?
How do I fix CVE-2024-5647?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2024
- CVE-2024-56462IBM QRadar 7.5.0 through 7.5.0 UP15 Interim Fix 002 could al…8.8
- CVE-2024-56463IBM QRadar SIEM 7.5 is vulnerable to cross-site scripting. T…4.8
- CVE-2024-56464IBM QRadar SIEM 7.5 - 7.5.0 UP14 IF01 is affected by an info…2.7
- CVE-2024-56467IBM EntireX 11.1 could allow a local user to obtain sensitiv…3.3
- CVE-2024-56468IBM InfoSphere Data Replication VSAM for z/OS Remote Source …6.5
- CVE-2024-56469IBM UrbanCode Deploy (UCD) 7.1 through 7.1.2.22, 7.2 through…6.3
- CVE-2024-56470IBM Aspera Shares 1.9.0 through 1.10.0 PL6 is vulnerable to…5.4
- CVE-2024-56471IBM Aspera Shares 1.9.0 through 1.10.0 PL6 is vulnerable to…5.4
- CVE-2024-56472IBM Aspera Shares 1.9.0 through 1.10.0 PL6 is vulnerable to…5.4
- CVE-2024-56473IBM Aspera Shares 1.9.0 through 1.10.0 PL6 could allow an a…5.3
- CVE-2024-56474IBM TXSeries for Multiplatforms 9.1 and 11.1 is vulnerable t…8.8
- CVE-2024-56475IBM TXSeries for Multiplatforms 9.1 and 11.1 is vulnerable t…5.4
Are you affected by CVE-2024-5647?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
