CVE-2024-8713
CVSS 3.1 Score 6.1 of 10 (medium)
Details
Published Sep 25, 2024
Updated: Oct 2, 2024
CWE ID 79
Summary
CVE-2024-8713 is a Reflected Cross-Site Scripting (XSS) vulnerability affecting the Kodex Posts Likes plugin for WordPress. This issue, present in all versions up to 2.5.0, arises due to the inadequate escaping of URLs when using add_query_arg. An attacker can exploit this flaw by injecting malicious web scripts, which may lead to unauthorized access or data theft. Successful exploitation requires tricking a user into clicking a malicious link. This vulnerability poses a significant risk, emphasizing the importance of timely updates for WordPress plugins.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.