CVE-2024-11607

CVSS 3.1 Score 6.1 of 10 (medium)

Details

Published Dec 21, 2024
Updated: Dec 27, 2024

Summary

CVE-2024-11607 is a vulnerability affecting the GTPayment Donations plugin for WordPress. This issue allows attackers to inject Stored Cross-Site Scripting (XSS) payloads through a Cross-Site Request Forgery (CSRF) attack. The plugin fails to implement CSRF protection in certain areas and lacks input sanitization and escaping, enabling an attacker to manipulate user data and potentially take control of admin sessions. This poses a significant risk to websites using the vulnerable plugin version and could lead to data theft or unauthorized actions. Upgrading to the latest, secure version is strongly recommended to mitigate this threat.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share