CVE-2024-8282
Vowelweb
CVE-2024-8282 is a Stored Cross-Site Scripting (XSS) vulnerability in the Ibtana – WordPress Website Builder plugin. This flaw allows authenticated attackers with contributor access or higher to inject malicious web scripts into WordPress pages. These scripts execute when any user visits the compromised page.
Specifically, the 'align' attribute within the 'wp:ive/ive-productscarousel' Gutenberg block lacks proper sanitization. Although the CVSS score is 5.4, indicating medium severity, the SOCRadar Vulnerability Risk Score (SVRS) of 53 suggests a moderate level of real-world risk. Exploitation could lead to session hijacking, defacement, or redirection to malicious sites. The vulnerability exists in versions up to 1.2.4.4 of the plugin, making it critical for website administrators to update immediately. The presence of a CWE-79 classification highlights the common nature of cross-site scripting vulnerabilities.
Indicators of Compromise
Exploits
News
Social Media
Affected Software
References
CWE Details
CVE Radar
Real-time CVE Intelligence & Vulnerability Management Platform
CVE Radar provides comprehensive vulnerability intelligence by monitoring CVE databases, security advisories, and threat feeds. Get instant updates on new vulnerabilities, exploit details, and mitigation strategies specific to your assets.