CVE-2024-9218

CVSS 3.1 Score 6.1 of 10 (medium)

Details

Published Oct 2, 2024
Updated: Oct 8, 2024
CWE ID 79

Summary

CVE-2024-9218 identifies a vulnerability in the Magazine Blocks plugin for WordPress, affecting all versions up to 1.3.14. This vulnerability allows unauthenticated attackers to exploit reflected cross-site scripting (XSS) by using the add_query_arg function without proper URL escaping, enabling them to inject malicious scripts into web pages if a user is tricked into clicking a link. To remediate this issue, users should update the plugin to the latest version that addresses the vulnerability, as detailed in the provided patch references. The potential danger posed includes low integrity and confidentiality impacts, but requires user interaction for exploitation, leading to a medium severity rating of 6.1 on the CVSS scale. Organizations utilizing this plugin should take immediate action to mitigate risks associated with this vulnerability.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share