CVE-2024-9457

CVSS 3.1 Score 5.4 of 10 (medium)

Details

Published Oct 10, 2024
Updated: Oct 15, 2024
CWE ID 79

Summary

CVE-2024-9457 is a stored Cross-Site Scripting (XSS) vulnerability affecting the WP Builder plugin for WordPress. This issue, present in all versions up to 3.0.7, allows authenticated attackers with Author-level access or higher to inject malicious web scripts into SVG files. Successful exploitation enables the attacker to execute these scripts whenever a user views the affected files, potentially leading to unintended actions or data exposure.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share