CVE-2024-8872
CVSS 3.1 Score 6.1 of 10 (medium)
Details
Published Sep 26, 2024
Updated: Oct 1, 2024
CWE ID 79
CWE ID 80
Summary
CVE-2024-8872 is a Reflected Cross-Site Scripting (XSS) vulnerability affecting the Store Hours plugin for WordPress, versions up to and including 4.3.20. Unauthenticated attackers can exploit this issue by injecting malicious scripts into URLs through the use of add_query_arg without proper escaping. Successful attacks require users to perform actions like clicking on malicious links, resulting in potentially harmful code execution on affected pages.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.