CVE-2024-5029

CVSS 3.1 Score 5.5 of 10 (medium)

Details

Published Nov 21, 2024
CWE ID 908

Summary

CVE-2024-5029 is a vulnerability affecting the CM Table Of Contents WordPress plugin before version 1.2.4. This issue allows attackers to inject Stored XSS (Cross-Site Scripting) payloads via a Cross-Site Request Forgery (CSRF) attack. The plugin fails to implement CSRF protection when updating settings, and lacks proper sanitization and escaping, creating an exploitable scenario. Successful attacks could result in the injection of malicious scripts that could affect the behavior or appearance of the website for unsuspecting users. Administrators are strongly advised to update to the latest plugin version to mitigate this risk.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share