CVE-2024-24713

CVSS 3.1 Score 5.4 of 10 (medium)

Details

Published Feb 10, 2024
Updated: Feb 16, 2024
CWE ID 79

Summary

CVE-2024-24713 is a Cross-site Scripting (XSS) vulnerability affecting the WP Auto Listings Auto Listings – Car Listings & Car Dealership Plugin for WordPress, from version n/a through 2.6.5. An attacker can exploit this improper neutralization of input during web page generation issue to inject malicious scripts into the plugin, resulting in unintended execution of code in users' browsers. This could potentially lead to unauthorized access, data theft, or manipulation of the affected WordPress site. It is essential to update the plugin to the latest version as soon as possible to mitigate this risk.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share