CVE-2024-9883
Last modified
CVE-2024-9883 is a medium-severity vulnerability rated 4.8/10 on the CVSS scale. The Pods WordPress plugin before 3.2.7.1 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).. EPSS estimates a 0.36% chance of exploitation in the next 30 days.
Description
The Pods WordPress plugin before 3.2.7.1 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).
Metrics
CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Podsfoundation | Pods | < 3.2.7.1 |
References
- https://wpscan.com/vulnerability/ea4b277e-ef47-4e38-bd82-c5a54a95372f/Exploit, Third Party Advisory
Timeline
- Published
- Last Modified
- Status
- Analyzed
Frequently Asked Questions
What is CVE-2024-9883?
How severe is CVE-2024-9883?
How do I fix CVE-2024-9883?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2024
- CVE-2024-9877: Use of GET Request Method With Sensitive Query Strings vul…5.3
- CVE-2024-9878The Photo Gallery by 10Web – Mobile-Friendly Image Gallery p…4.8
- CVE-2024-9879The Melapress File Monitor WordPress plugin before 2.1.1 doe…5.4
- CVE-2024-9880Rejected reason: This CVE ID has been rejected or withdrawn …
- CVE-2024-9881The LearnPress WordPress plugin before 4.2.7.2 does not san…4.8
- CVE-2024-9882The Salon Booking System, Appointment Scheduling for Salons,…4.8
- CVE-2024-9884The T(-) Countdown plugin for WordPress is vulnerable to Sto…6.4
- CVE-2024-9885The Widget or Sidebar Shortcode plugin for WordPress is vuln…6.4
- CVE-2024-9886The WP Baidu Map plugin for WordPress is vulnerable to Store…6.4
- CVE-2024-9887The Login using WordPress Users ( WP as SAML IDP ) plugin fo…7.2
- CVE-2024-9888The ElementInvader Addons for Elementor plugin for WordPress…5.4
- CVE-2024-9889The ElementInvader Addons for Elementor plugin for WordPress…4.3
Are you affected by CVE-2024-9883?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
