CVE-2024-9127

CVSS 3.1 Score 5.4 of 10 (medium)

Details

Published Sep 26, 2024
Updated: Oct 1, 2024
CWE ID 79

Summary

CVE-2024-9127 is a Stored Cross-Site Scripting (XSS) vulnerability affecting the Super Testimonials plugin for WordPress. This issue, present in all versions up to 3.0.0, allows authenticated attackers with Contributor-level access or higher to inject arbitrary web scripts. The vulnerability is due to insufficient input sanitization and output escaping of the ‘alignment’ parameter. Consequently, when a user visits an injected page, the injected scripts will execute, posing a potential security risk.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share