CVE-2024-9609

CVSS 3.1 Score 6.1 of 10 (medium)

Details

Published Nov 15, 2024
CWE ID 79

Summary

CVE-2024-9609 is a Reflected Cross-Site Scripting (XSS) vulnerability affecting the LearnPress Export Import plugin for WordPress, versions up to and including 4.0.4. This issue stems from insufficient input sanitization and output escaping of the 'learnpress_import_form_server' parameter. Malicious actors can exploit this vulnerability by injecting arbitrary web scripts, allowing them to execute unwanted code on users' pages. Successful exploitation requires tricking a user into performing an action, such as clicking on a malicious link.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share