CVE-2024-5029
CVSS 3.1 Score 5.5 of 10 (medium)
Details
Summary
CVE-2024-5029 is a vulnerability affecting the CM Table Of Contents WordPress plugin before version 1.2.4. This issue allows attackers to inject Stored XSS (Cross-Site Scripting) payloads via a Cross-Site Request Forgery (CSRF) attack. The plugin fails to implement CSRF protection when updating settings, and lacks proper sanitization and escaping, creating an exploitable scenario. Successful attacks could result in the injection of malicious scripts that could affect the behavior or appearance of the website for unsuspecting users. Administrators are strongly advised to update to the latest plugin version to mitigate this risk.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.
Affected Products
- Linux Kernel
Affected Vendors
- LINUX