CVE-2024-9775
CVSS 3.1 Score 5.5 of 10 (medium)
Details
Summary
CVE-2024-9775 is a Stored Cross-Site Scripting (XSS) vulnerability affecting the Anih - Creative Agency WordPress Theme. This issue, which impacts all versions up to and including 2024, arises due to an incomplete blacklist, insufficient input sanitization, and lacking output escaping in the theme's admin settings. Consequently, authenticated attackers with administrator-level permissions can inject malicious web scripts into pages. Suchscripts will execute whenever a user accesses an affected page, posing a significant threat to multi-site installations and those with unfiltered_html disabled.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.