CVE-2024-8857

CVSS 3.1 Score 4.8 of 10 (medium)

Details

Published Jan 7, 2025
CWE ID 79

Summary

CVE-2024-8857 is a vulnerability affecting the WordPress Auction Plugin before version 3.7. This issue permits high privilege users, such as editors, to execute stored Cross-Site Scripting (XSS) attacks due to insufficient sanitization and escaping of plugin settings. Successful exploitation could result in code injection, data theft, or unauthorized user actions within the plugin. It is essential for WordPress users to update the plugin to the latest version as soon as possible to mitigate this risk.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share