CVE-2024-4753
Wpexperts
CVE-2024-4753: Stored Cross-Site Scripting (XSS) vulnerability in the WP Secure Maintenance WordPress plugin. This flaw allows authenticated users with high privileges, such as administrators, to inject malicious scripts into website settings. Exploitation can occur even when the unfiltered_html capability is disabled. The WP Secure Maintenance WordPress plugin versions prior to 1.7 are affected. While the CVSS score is 4.8, the SVRS is 38, suggesting a moderate risk level. This vulnerability could be leveraged to compromise administrator accounts or inject malicious content into the website. Website owners using the WP Secure Maintenance plugin should update to version 1.7 or later to mitigate this security risk.
Indicators of Compromise
Exploits
News
Social Media
Affected Software
References
CWE Details
CVE Radar
Real-time CVE Intelligence & Vulnerability Management Platform
CVE Radar provides comprehensive vulnerability intelligence by monitoring CVE databases, security advisories, and threat feeds. Get instant updates on new vulnerabilities, exploit details, and mitigation strategies specific to your assets.