CVE-2024-11808
CVE-2024-11808: A reflected Cross-Site Scripting (XSS) vulnerability exists in the Pingmeter Uptime Monitoring plugin for WordPress, versions 1.0.3 and earlier. Unauthenticated attackers can inject malicious web scripts by exploiting insufficient sanitization of the '_wpnonce' parameter. This means attackers can execute arbitrary JavaScript in a user's browser if they can trick the user into clicking a specially crafted link. The SVRS score of 30 indicates a low level of risk, suggesting that while exploitable, it is not currently considered a high-priority threat. However, XSS vulnerabilities can be used to steal cookies, redirect users, or deface websites. This vulnerability is significant because it affects a widely used WordPress plugin, potentially impacting numerous websites if exploited. Mitigating this requires updating to a patched version or disabling the plugin until an update is available. Although currently considered a lower risk, it could become more dangerous if it begins to be actively exploited in the wild.
Indicators of Compromise
Exploits
News
Social Media
Affected Software
References
CWE Details
CVE Radar
Real-time CVE Intelligence & Vulnerability Management Platform
CVE Radar provides comprehensive vulnerability intelligence by monitoring CVE databases, security advisories, and threat feeds. Get instant updates on new vulnerabilities, exploit details, and mitigation strategies specific to your assets.