CVE-2024-5004
Cminds
CVE-2024-5004: WordPress CM Popup Plugin is vulnerable to Stored Cross-Site Scripting (XSS). This flaw allows high-privilege users, like contributors, to inject malicious scripts into campaign settings. Before version 1.6.6, the plugin fails to properly sanitize and escape user input, creating an avenue for attack. Given its SVRS score of 49, it represents a moderate risk. While not immediately critical, it should be addressed to prevent potential account compromise or website defacement. Exploiting this vulnerability could lead to unauthorized actions performed by compromised user accounts and potentially malicious code execution.
Indicators of Compromise
Exploits
News
Social Media
Affected Software
References
CWE Details
CVE Radar
Real-time CVE Intelligence & Vulnerability Management Platform
CVE Radar provides comprehensive vulnerability intelligence by monitoring CVE databases, security advisories, and threat feeds. Get instant updates on new vulnerabilities, exploit details, and mitigation strategies specific to your assets.