CVE-2024-12626
CVSS 3.1 Score 9.6 of 10 (high)
Details
Summary
CVE-2024-12626 is a Reflected Cross-Site Scripting (XSS) vulnerability affecting the AutomatorWP plugin for WordPress, versions up to and including 5.0.9. The vulnerability occurs due to insufficient input sanitization and output escaping in the 'a-0-o-search_field_value' parameter. An attacker can exploit this flaw by injecting arbitrary web scripts into pages, potentially executing malicious code. Unauthenticated attackers can trick users into performing an action, such as clicking a link, to trigger the vulnerability. If the import and code action feature is used, an attacker can leverage this vulnerability for more severe consequences.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.