CVE-2024-7489

CVSS 3.1 Score 4.4 of 10 (medium)

Details

Published Oct 12, 2024
Updated: Oct 16, 2024
CWE ID 79

Summary

CVE-2024-7489 is a stored Cross-Site Scripting (XSS) vulnerability affecting the Forms for Mailchimp by Optin Cat plugin for WordPress. This issue, found in versions up to 2.5.6, allows authenticated attackers with editor-level access to inject malicious scripts into form color parameters. These scripts are executed when users visit injected pages, posing a significant security risk. The flaw stems from insufficient input sanitization and output escaping in the plugin.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share