CVE-2024-22150
CVSS 3.1 Score 5.4 of 10 (medium)
Details
Summary
CVE-2024-22150 is a Cross-site Scripting (XSS) vulnerability affecting the PowerFolio plugin for WordPress, specifically its Portfolio & Image Gallery feature. The flaw, named Stored XSS, allows attackers to inject malicious scripts into web pages generated by the plugin, potentially stealing user data or taking control of user sessions. This vulnerability affects PowerFolio from all versions up to and including 3.1. Successful exploitation could lead to significant security risks and potential data breaches. Users are strongly advised to update to the latest version of the plugin as soon as possible to mitigate this threat.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.