CVE-2024-12457

CVSS 3.1 Score 6.4 of 10 (medium)

Details

Published Jan 7, 2025
CWE ID 79

Summary

CVE-2024-12457 is a stored Cross-Site Scripting (XSS) vulnerability affecting the Chat Support for Viber plugin for WordPress. The issue lies in the 'vchat' shortcode's insufficient sanitization and output escaping of user-supplied attributes. This defect enables authenticated attackers, who have contributor-level access or higher, to inject malicious web scripts. These scripts execute whenever a user visits an injected page, potentially leading to unintended actions or data theft. Versions up to and including 1.7.2 are impacted.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share