CVE-2024-2278
CVE-2024-2278 is a Stored Cross-Site Scripting (XSS) vulnerability in the Themify WordPress plugin. Prior to version 1.4.4, the plugin fails to properly sanitize and escape certain filter settings, potentially allowing high-privilege users, such as admins, to inject malicious scripts. This can occur even when the unfiltered_html capability is disallowed, a common security measure in multisite WordPress installations. With an SVRS of 30, this vulnerability is considered low severity, indicating a lower risk profile compared to vulnerabilities with higher scores. However, successful exploitation could still lead to account compromise and malicious code injection into the website. While not requiring immediate action, patching is recommended to mitigate potential risks associated with this XSS flaw.
Indicators of Compromise
Exploits
News
Social Media
Affected Software
References
CWE Details
CVE Radar
Real-time CVE Intelligence & Vulnerability Management Platform
CVE Radar provides comprehensive vulnerability intelligence by monitoring CVE databases, security advisories, and threat feeds. Get instant updates on new vulnerabilities, exploit details, and mitigation strategies specific to your assets.