CVE-2024-2130
CVSS 3.1 Score 6.7 of 10 (medium)
Details
Published Mar 12, 2024
Updated: Mar 13, 2024
CWE ID 284
Summary
CVE-2024-2130 is a Stored Cross-Site Scripting (XSS) vulnerability affecting the CWW Companion plugin for WordPress. This issue, present in all versions up to 1.2.7, allows authenticated attackers with contributor-level access or higher to inject malicious scripts into the Module2 widget. As a result, any user who accesses a page with an injected script will unintentionally execute the malicious code. The root cause of this vulnerability lies in the lack of adequate input sanitization and output escaping for user-supplied attributes.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.
Affected Products
- Microsoft Windows 10
- Microsoft Windows 11
Affected Vendors
- Microsoft