CVE-2024-8239

CVSS 3.1 Score 5.4 of 10 (medium)

Details

Published Sep 30, 2024
Updated: Oct 7, 2024
CWE ID 79

Summary

CVE-2024-8239 is a new vulnerability affecting the Starbox WordPress plugin before version 3.5.3. This issue stems from the plugin's failure to sanitize social media profiles URLs, making it susceptible to Stored Cross-Site Scripting (XSS) attacks. Malicious users with a minimum contributor role can exploit this vulnerability by injecting malicious scripts into stars or comments sections. These attacks can potentially harm site visitors or gain unauthorized access to sensitive information. To mitigate this risk, WordPress users are advised to update to the latest version of the Starbox plugin as soon as possible.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share