CVE-2024-9232
CVSS 3.1 Score 6.1 of 10 (medium)
Details
Published Oct 11, 2024
Updated: Oct 15, 2024
CWE ID 79
Summary
CVE-2024-9232 is a Reflected Cross-Site Scripting (XSS) vulnerability affecting the "Download Plugins and Themes in ZIP from Dashboard" plugin for WordPress. The issue lies in the use of the function 'add_query_arg' without proper escaping in URLs, allowing unauthenticated attackers to inject arbitrary web scripts. Successful exploitation of this vulnerability requires users to be tricked into performing an action, such as clicking on a malicious link, potentially leading to compromised pages. Versions up to and including 1.9.1 are reportedly affected.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.