CVE-2024-55864

CVSS 3.0 Score 4.8 of 10 (medium)

Details

Published Dec 17, 2024
CWE ID 79

Summary

CVE-2024-55864 is a cross-site scripting (XSS) vulnerability affecting My WP Customize Admin and Frontend versions before 1.24.1. Malicious administrative users can exploit this issue by customizing the administrative page with malicious content. When other users access the page, an arbitrary script may be executed in their web browser, potentially leading to unintended actions or data theft. The vulnerability poses a significant risk to the security of user data and requires immediate patching.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share