CVE-2024-11607
CVSS 3.1 Score 6.1 of 10 (medium)
Details
Summary
CVE-2024-11607 is a vulnerability affecting the GTPayment Donations plugin for WordPress. This issue allows attackers to inject Stored Cross-Site Scripting (XSS) payloads through a Cross-Site Request Forgery (CSRF) attack. The plugin fails to implement CSRF protection in certain areas and lacks input sanitization and escaping, enabling an attacker to manipulate user data and potentially take control of admin sessions. This poses a significant risk to websites using the vulnerable plugin version and could lead to data theft or unauthorized actions. Upgrading to the latest, secure version is strongly recommended to mitigate this threat.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.