CVE-2024-10577

CVSS 3.1 Score 6.1 of 10 (medium)

Details

Published Nov 13, 2024
CWE ID 79

Summary

CVE-2024-10577 is a Reflected Cross-Site Scripting (XSS) vulnerability affecting the Fat Rat Collect plugin for WordPress. The flaw, present in all versions up to 2.7.3, arises due to a missing URL escaping mechanism. An attacker can exploit this vulnerability by injecting malicious scripts into URLs, which can be executed when an unsuspecting user clicks on a specially crafted link. This vulnerability poses a significant risk as it does not require authentication, making it easier for attackers to launch attacks and potentially gain unauthorized access to user data or take control of their WordPress sites.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share