CVE-2024-29804
CVE-2024-29804: Stored XSS vulnerability in Team Heateor Fancy Comments WordPress plugin. This allows attackers to inject malicious scripts into web pages, impacting users from n/a through version 1.2.14. Despite a CVSS score of 0, indicating a base score, SOCRadar's Vulnerability Risk Score (SVRS) of 30 suggests a low, but not negligible risk. The Stored XSS means that the injected script is permanently stored on the server, affecting every user who visits the affected page. This can lead to data theft, session hijacking, or defacement of the website. Website administrators should update their Fancy Comments WordPress plugin immediately to mitigate the security risk, even with the low SVRS. While the threat is not deemed 'critical' (SVRS above 80), proactive patching is crucial to maintain website integrity and user trust.
Indicators of Compromise
Exploits
News
Social Media
Affected Software
References
CWE Details
CVE Radar
Real-time CVE Intelligence & Vulnerability Management Platform
CVE Radar provides comprehensive vulnerability intelligence by monitoring CVE databases, security advisories, and threat feeds. Get instant updates on new vulnerabilities, exploit details, and mitigation strategies specific to your assets.