CVE-2024-1056
Funnelkit
CVE-2024-1056: A WordPress plugin vulnerability exists in FunnelKit Funnel Builder Pro, potentially allowing malicious script injection. This vulnerability lies within the 'allow_iframe_tag_in_post' function, globally permitting script and iframe tags in posts. The Stored Cross-Site Scripting (XSS) vulnerability impacts versions up to 3.4.5. Authenticated attackers with contributor access or higher can inject arbitrary web scripts. Although the CVSS score is 5.4, the SOCRadar Vulnerability Risk Score (SVRS) of 53 indicates a moderate risk. While not critical (SVRS > 80), this vulnerability could allow attackers to execute scripts when users access affected pages, potentially leading to session hijacking or defacement.
Indicators of Compromise
Exploits
News
Social Media
Affected Software
References
CWE Details
CVE Radar
Real-time CVE Intelligence & Vulnerability Management Platform
CVE Radar provides comprehensive vulnerability intelligence by monitoring CVE databases, security advisories, and threat feeds. Get instant updates on new vulnerabilities, exploit details, and mitigation strategies specific to your assets.