CVE-2024-9426
CVSS 3.1 Score 6.4 of 10 (medium)
Details
Published Nov 13, 2024
CWE ID 79
Summary
CVE-2024-9426 is a Stored Cross-Site Scripting (XSS) vulnerability affecting the Aqua SVG Sprite plugin for WordPress. This issue, present in all versions up to 3.0.14, allows authenticated attackers with Author-level access or above to upload SVG files with malicious scripts. The plugin's insufficient input sanitization and output escaping fail to protect against such attacks, resulting in the execution of arbitrary web scripts whenever a user accesses the infected SVG file.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.