CVE-2024-8712
CVSS 3.1 Score 6.1 of 10 (medium)
Details
Published Sep 28, 2024
Updated: Oct 7, 2024
CWE ID 79
Summary
CVE-2024-8712: The GTM Server Side plugin for WordPress, used in versions up to 2.1.19, contains a Reflected Cross-Site Scripting (XSS) vulnerability. This flaw is due to the plugin's failure to properly escape URLs in add_query_arg function, leading to the injection of arbitrary web scripts. Unauthenticated attackers can exploit this vulnerability by tricking users into clicking malicious links, resulting in the execution of malicious code on affected pages.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.
Affected Vendors
- St. Ape