CVE-2024-38689
CVE-2024-38689: Stored Cross-Site Scripting (XSS) vulnerability in the Simple Popup plugin. This allows attackers to inject malicious scripts into web pages, affecting users who interact with the compromised popup. Specifically, versions up to and including 4.4 of the Simple Popup plugin are vulnerable. Although the CVSS score is 0, indicating no immediate risk according to that system, the SOCRadar Vulnerability Risk Score (SVRS) of 30 suggests there is a potential for exploitation. This is due to the fact that it is tagged as In The Wild. While not critical (SVRS > 80), the presence of the vulnerability creates a risk of attackers injecting malicious scripts, leading to potential data theft or unauthorized actions on the affected website. Website administrators should update the Simple Popup plugin to a patched version or remove it entirely to mitigate the security risk. The impact could range from defacement to credential harvesting, underscoring the need for proactive security measures.
Indicators of Compromise
Exploits
News
Social Media
Affected Software
References
CWE Details
CVE Radar
Real-time CVE Intelligence & Vulnerability Management Platform
CVE Radar provides comprehensive vulnerability intelligence by monitoring CVE databases, security advisories, and threat feeds. Get instant updates on new vulnerabilities, exploit details, and mitigation strategies specific to your assets.