CVE-2024-9267

CVSS 3.1 Score 6.1 of 10 (medium)

Details

Published Oct 1, 2024
Updated: Oct 4, 2024
CWE ID 79

Summary

CVE-2024-9267 is a Reflected Cross-Site Scripting (XSS) vulnerability affecting the Easy WordPress Subscribe – Optin Hound plugin. Versions up to and including 1.4.3 are vulnerable due to the use of add_query_arg without proper escaping in URLs. Attackers can exploit this flaw by injecting arbitrary web scripts, allowing them to execute malicious code on a user's browser when they visit a specially crafted page. This can lead to data theft, account takeover, or other unintended consequences, highlighting the importance of keeping WordPress installations updated.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share