CVE-2024-3245
CVSS 3.1 Score 9.8 of 10 (high)
Details
Published Apr 6, 2024
Updated: Jan 7, 2025
CWE ID 125
Summary
CVE-2024-3245 designates a stored Cross-Site Scripting (XSS) vulnerability affecting the EmbedPress plugin for WordPress, specifically its Youtube block, in versions up to 3.9.14. This issue stems from inadequate input sanitization and output escaping on user-supplied attributes. Consequently, authenticated attackers, who possess contributor-level access or higher, can inject malicious web scripts. These scripts will execute whenever a user accesses a manipulated page, posing a significant threat to website security.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.
Share
Affected Products
- FreeRDP
Affected Vendors
- Freerdp