CVE-2024-12738
CVSS 3.1 Score 6.1 of 10 (medium)
Details
Summary
CVE-2024-12738 is a Stored Cross-Site Scripting (XSS) vulnerability affecting the User Profile Builder plugin for WordPress, versions up to and including 3.12.9. The issue arises due to insufficient input sanitization and output escaping of several user meta parameters. An attacker can exploit this vulnerability to inject arbitrary web scripts that execute when a user accesses an injected page and clicks a link to show user meta. This vulnerability poses a significant risk, as it allows unauthenticated attackers to compromise user sessions and potentially gain control of WordPress sites. Users are strongly advised to update the plugin to the latest version as soon as possible to mitigate this threat.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.