CVE Radar Logo
CVERadar
CVE Radar Logo
CVERadar

CVE-2024-8505

High Severity
Connekthq
SVRS
53/100

CVSSv3
5.4/10

EPSS
0.00036/1

CVE-2024-8505 is a Stored Cross-Site Scripting (XSS) vulnerability affecting the WordPress Infinite Scroll – Ajax Load More plugin. This flaw allows attackers with Contributor-level access or higher to inject malicious web scripts into website pages. These scripts execute whenever a user visits a compromised page. Due to insufficient input sanitization of the 'button_label' parameter, attackers can inject arbitrary web scripts. The SOCRadar Vulnerability Risk Score (SVRS) for CVE-2024-8505 is 53, indicating a moderate risk but should still be addressed promptly to prevent potential account compromise and data theft. While the CVSS score is 5.4, the XSS vulnerability makes it essential to update to a patched version to mitigate the risk of attacker activity. Immediate patching is highly recommended even with a moderate SVRS.

In The Wild
CVSS:3.1
AV:N
AC:L
PR:L
UI:R
S:C
C:L
I:L
A:N
2024-10-02

2024-10-07
Eye Icon
SOCRadar
AI Insight

Description

CVE-2024-8505 is a Stored Cross-Site Scripting (XSS) vulnerability in the WordPress Infinite Scroll – Ajax Load More plugin. It allows authenticated attackers with Contributor-level access or higher to inject malicious scripts into pages, which will execute when users access those pages. This could lead to account takeover, data theft, or other malicious activities.

Key Insights

  • SVRS of 42: This indicates a moderate risk, requiring attention and monitoring.
  • Authenticated attackers: Only users with Contributor-level access or higher can exploit this vulnerability.
  • Active exploits: There are no known active exploits for this vulnerability at this time.
  • CISA warning: CISA has not issued a warning for this vulnerability.

Mitigation Strategies

  • Update the WordPress Infinite Scroll – Ajax Load More plugin to version 7.1.3 or later.
  • Implement input validation and output escaping to prevent malicious scripts from being injected.
  • Restrict access to the plugin's settings to only authorized users.
  • Monitor for suspicious activity and take appropriate action if necessary.

Additional Information

If you have any further questions regarding this incident, you can use the 'Ask to Analyst' feature, contact SOCRadar directly, or open a support ticket for more information.

Indicators of Compromise

No IOCs found for this CVE

Exploits

No exploits found for this CVE

Enhance Your CVE Management with SOCRadar Vulnerability Intelligence
Get comprehensive CVE details, real-time notifications, and proactive threat management all in one platform.
CVE Details
Access comprehensive CVE information instantly
Real-time Tracking
Subscribe to CVEs and get instant updates
Exploit Analysis
Monitor related APT groups and threats
IOC Tracking
Analyze and track CVE-related IOCs

News

CVE-2024-8505 | Infinite Scroll Plugin up to 7.1.2 on WordPress button_label cross site scripting
vuldb.com2024-10-01
CVE-2024-8505 | Infinite Scroll Plugin up to 7.1.2 on WordPress button_label cross site scripting | A vulnerability was found in Infinite Scroll Plugin up to 7.1.2 on WordPress and classified as problematic. Affected by this issue is some unknown functionality. The manipulation of the argument button_label leads to cross site scripting. This vulnerability is handled as CVE-2024-8505. The attack may
cve-2024-8505
domains
urls
cves

Social Media

CVE-2024-8505 The WordPress Infinite Scroll – Ajax Load More plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘button_label’ parameter in all versions up to,… https://t.co/VITca5mMhJ
0
0
0

Affected Software

Configuration 1
TypeVendorProduct
AppConnekthqajax_load_more

References

ReferenceLink
[email protected]https://plugins.trac.wordpress.org/browser/ajax-load-more/trunk/core/classes/class-alm-shortcode.php
[email protected]https://plugins.trac.wordpress.org/changeset/3160896/
[email protected]https://wordpress.org/plugins/ajax-load-more/#developers
[email protected]https://www.wordfence.com/threat-intel/vulnerabilities/id/ca29158a-ca60-46c7-93a5-bcf76e7666e4?source=cve

CWE Details

CWE IDCWE NameDescription
CWE-87Improper Neutralization of Alternate XSS SyntaxThe software does not neutralize or incorrectly neutralizes user-controlled input for alternate script syntax.
CWE-79Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')The software does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.

CVE Radar

Real-time CVE Intelligence & Vulnerability Management Platform

CVE Radar provides comprehensive vulnerability intelligence by monitoring CVE databases, security advisories, and threat feeds. Get instant updates on new vulnerabilities, exploit details, and mitigation strategies specific to your assets.

Get Free Vulnerability Intelligence AccessAccess real-time CVE monitoring, exploit analysis, and threat intelligence