CVE-2024-37248
CVE-2024-37248: Stored Cross-Site Scripting (XSS) vulnerability in CryoutCreations Anima WordPress theme. This XSS vulnerability allows attackers to inject malicious scripts into web pages, affecting users from Anima versions up to 1.4.1. The vulnerability stems from improper neutralization of input during web page generation, leading to stored XSS. While the CVSS score is 0, SOCRadar's Vulnerability Risk Score (SVRS) of 30 suggests a moderate level of risk. An SVRS of 30 indicates that, whilst not critical, this CVE still poses a threat and should be addressed. Successful exploitation could lead to data theft, session hijacking, or defacement of the website. It's important to update the Anima theme to a patched version to mitigate this risk.
Indicators of Compromise
Exploits
News
Social Media
Affected Software
References
CWE Details
CVE Radar
Real-time CVE Intelligence & Vulnerability Management Platform
CVE Radar provides comprehensive vulnerability intelligence by monitoring CVE databases, security advisories, and threat feeds. Get instant updates on new vulnerabilities, exploit details, and mitigation strategies specific to your assets.