CVE-2024-8505
Connekthq
CVE-2024-8505 is a Stored Cross-Site Scripting (XSS) vulnerability affecting the WordPress Infinite Scroll – Ajax Load More plugin. This flaw allows attackers with Contributor-level access or higher to inject malicious web scripts into website pages. These scripts execute whenever a user visits a compromised page. Due to insufficient input sanitization of the 'button_label' parameter, attackers can inject arbitrary web scripts. The SOCRadar Vulnerability Risk Score (SVRS) for CVE-2024-8505 is 53, indicating a moderate risk but should still be addressed promptly to prevent potential account compromise and data theft. While the CVSS score is 5.4, the XSS vulnerability makes it essential to update to a patched version to mitigate the risk of attacker activity. Immediate patching is highly recommended even with a moderate SVRS.
Description
CVE-2024-8505 is a Stored Cross-Site Scripting (XSS) vulnerability in the WordPress Infinite Scroll – Ajax Load More plugin. It allows authenticated attackers with Contributor-level access or higher to inject malicious scripts into pages, which will execute when users access those pages. This could lead to account takeover, data theft, or other malicious activities.
Key Insights
- SVRS of 42: This indicates a moderate risk, requiring attention and monitoring.
- Authenticated attackers: Only users with Contributor-level access or higher can exploit this vulnerability.
- Active exploits: There are no known active exploits for this vulnerability at this time.
- CISA warning: CISA has not issued a warning for this vulnerability.
Mitigation Strategies
- Update the WordPress Infinite Scroll – Ajax Load More plugin to version 7.1.3 or later.
- Implement input validation and output escaping to prevent malicious scripts from being injected.
- Restrict access to the plugin's settings to only authorized users.
- Monitor for suspicious activity and take appropriate action if necessary.
Additional Information
If you have any further questions regarding this incident, you can use the 'Ask to Analyst' feature, contact SOCRadar directly, or open a support ticket for more information.
Indicators of Compromise
Exploits
News
Social Media
Affected Software
References
CWE Details
CVE Radar
Real-time CVE Intelligence & Vulnerability Management Platform
CVE Radar provides comprehensive vulnerability intelligence by monitoring CVE databases, security advisories, and threat feeds. Get instant updates on new vulnerabilities, exploit details, and mitigation strategies specific to your assets.