CVE-2024-37117
Uncannyowl
CVE-2024-37117 is a reflected XSS vulnerability in the Uncanny Owl Uncanny Automator Pro plugin for WordPress. This cross-site scripting flaw allows attackers to inject malicious scripts into web pages viewed by users. Although the CVSS score is 6.1, the SOCRadar Vulnerability Risk Score (SVRS) is 58, indicating a moderate risk that should be addressed. The vulnerability affects Uncanny Automator Pro versions up to 5.3. An attacker could exploit this to steal sensitive information, hijack user sessions, or deface websites. The presence of the "In The Wild" tag suggests active exploitation may be occurring, so patching is advisable to mitigate potential threats associated with CWE-79.
Indicators of Compromise
Exploits
News
Social Media
Affected Software
References
CWE Details
CVE Radar
Real-time CVE Intelligence & Vulnerability Management Platform
CVE Radar provides comprehensive vulnerability intelligence by monitoring CVE databases, security advisories, and threat feeds. Get instant updates on new vulnerabilities, exploit details, and mitigation strategies specific to your assets.