CVE-2024-44045
CVSS 3.1 Score 4.8 of 10 (medium)
Details
Summary
CVE-2024-44045 is a newly disclosed Cross-site Scripting (XSS) vulnerability affecting WP Abstracts, a plugin used for managing abstracts and metadata in WordPress. The flaw, specifically an Improper Neutralization of Input During Web Page Generation issue, enables attackers to inject malicious code into stored web pages, potentially leading to unauthorized script execution and data theft when users visit the affected site. WP Abstracts versions from n/a to 2.6.5 are reportedly vulnerable to this stored XSS vulnerability. Users are encouraged to update to the latest release as soon as possible to mitigate the risk.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.