CVE-2024-3245

CVSS 3.1 Score 9.8 of 10 (high)

Details

Published Apr 6, 2024
Updated: Jan 7, 2025
CWE ID 125

Summary

CVE-2024-3245 designates a stored Cross-Site Scripting (XSS) vulnerability affecting the EmbedPress plugin for WordPress, specifically its Youtube block, in versions up to 3.9.14. This issue stems from inadequate input sanitization and output escaping on user-supplied attributes. Consequently, authenticated attackers, who possess contributor-level access or higher, can inject malicious web scripts. These scripts will execute whenever a user accesses a manipulated page, posing a significant threat to website security.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share