CVE-2024-9426

CVSS 3.1 Score 6.4 of 10 (medium)

Details

Published Nov 13, 2024
CWE ID 79

Summary

CVE-2024-9426 is a Stored Cross-Site Scripting (XSS) vulnerability affecting the Aqua SVG Sprite plugin for WordPress. This issue, present in all versions up to 3.0.14, allows authenticated attackers with Author-level access or above to upload SVG files with malicious scripts. The plugin's insufficient input sanitization and output escaping fail to protect against such attacks, resulting in the execution of arbitrary web scripts whenever a user accesses the infected SVG file.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share