CVE-2024-44045

CVSS 3.1 Score 4.8 of 10 (medium)

Details

Published Oct 6, 2024
Updated: Feb 27, 2025
CWE ID 79

Summary

CVE-2024-44045 is a newly disclosed Cross-site Scripting (XSS) vulnerability affecting WP Abstracts, a plugin used for managing abstracts and metadata in WordPress. The flaw, specifically an Improper Neutralization of Input During Web Page Generation issue, enables attackers to inject malicious code into stored web pages, potentially leading to unauthorized script execution and data theft when users visit the affected site. WP Abstracts versions from n/a to 2.6.5 are reportedly vulnerable to this stored XSS vulnerability. Users are encouraged to update to the latest release as soon as possible to mitigate the risk.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share