CVE-2024-10187
CVSS 3.1 Score 5.4 of 10 (medium)
Details
Summary
CVE-2024-10187: The myCred plugin for WordPress and WooCommerce, which provides loyalty points and rewards functionality, contains a Stored Cross-Site Scripting (XSS) vulnerability. The issue lies in the insufficient input sanitization and output escaping of user-supplied attributes for the mycred_link shortcode. This flaw enables authenticated attackers with contributor-level access and above to inject malicious web scripts. Consequently, any page accessed by an unsuspecting user will execute the injected scripts. Versions up to and including 2.7.4 of the plugin are affected by this vulnerability.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.