CVE-2024-9267
CVSS 3.1 Score 6.1 of 10 (medium)
Details
Summary
CVE-2024-9267 is a Reflected Cross-Site Scripting (XSS) vulnerability affecting the Easy WordPress Subscribe – Optin Hound plugin. Versions up to and including 1.4.3 are vulnerable due to the use of add_query_arg without proper escaping in URLs. Attackers can exploit this flaw by injecting arbitrary web scripts, allowing them to execute malicious code on a user's browser when they visit a specially crafted page. This can lead to data theft, account takeover, or other unintended consequences, highlighting the importance of keeping WordPress installations updated.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.