CVE-2024-12100
CVSS 3.1 Score 6.1 of 10 (medium)
Details
Summary
CVE-2024-12100 is a Reflected Cross-Site Scripting (XSS) vulnerability affecting the Bitcoin Lightning Publisher plugin for WordPress. Versions up to and including 1.4.1 are vulnerable to this issue. Hackers can exploit this weakness by injecting arbitrary web scripts into pages of a WordPress site, potentially gaining unauthorized access to user data or performing malicious actions. This vulnerability is triggered when the add_query_arg function is used without proper escaping on URLs in the plugin. Unauthenticated attackers can take advantage of this flaw by persuading users to click on a specially crafted link, leading to the execution of malicious code in their web browser.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.