CVE-2024-13426
CVSS 3.1 Score 5.4 of 10 (medium)
Details
Summary
CVE-2024-13426 is a vulnerability affecting the WP-Polls plugin for WordPress. In all versions up to 2.77.2, the plugin fails to properly escape user-supplied cookies, allowing unauthenticated attackers to inject additional SQL queries into existing ones. These queries are stored but not displayed, preventing attackers from gaining database information. However, a successful attack can lead to Stored Cross-Site Scripting, where malicious JavaScript is injected into the plugin. This vulnerability poses a significant security risk and requires immediate patching.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.