CVE-2024-8800
CVSS 3.1 Score 6.1 of 10 (medium)
Details
Summary
CVE-2024-8800: The WordPress plugin RabbitLoader, used for website speed optimization, contains a Reflected Cross-Site Scripting vulnerability. The issue arises due to the plugin's failure to properly escape URLs used with add_query_arg in all versions up to 2.21.0. Attackers can exploit this flaw by injecting malicious web scripts into pages, which execute if a user is tricked into taking a specific action like clicking a malicious link. Unauthenticated attackers can potentially gain control over user sessions and steal sensitive information. It is crucial for users to update their plugin to the latest version or consider removing it if it's no longer needed.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.