CVE-2024-8680
Ibericode
CVE-2024-8680 is a Stored Cross-Site Scripting (XSS) vulnerability in the MC4WP: Mailchimp for WordPress plugin. This flaw allows attackers with administrator privileges to inject malicious web scripts into website pages. While the CVSS score is 5.5, the SOCRadar Vulnerability Risk Score (SVRS) is 54, indicating a moderate risk. This vulnerability affects multi-site WordPress installations and those with unfiltered_html disabled. Exploitation can lead to arbitrary code execution in a user's browser when they visit the compromised page, enabling attackers to steal credentials, deface websites, or redirect users to malicious sites. Although not considered critical based on the SVRS, immediate patching is recommended to prevent potential security breaches and maintain the integrity of WordPress websites using the vulnerable plugin. The significance of this CVE lies in the potential for widespread compromise across affected WordPress instances.
Description:
CVE-2024-8680 is a Stored Cross-Site Scripting (XSS) vulnerability in the MC4WP: Mailchimp for WordPress plugin for WordPress. It allows authenticated attackers with administrator-level permissions to inject malicious scripts into pages, which will execute when users access those pages. This vulnerability only affects multi-site installations and installations where unfiltered_html has been disabled.
Key Insights:
- SVRS Score: 38 (Moderate)
- Exploit Status: Active exploits have been published.
- CISA Warnings: The Cybersecurity and Infrastructure Security Agency (CISA) has warned of the vulnerability, calling for immediate and necessary measures.
- In the Wild: The vulnerability is actively exploited by hackers.
Mitigation Strategies:
- Update the MC4WP: Mailchimp for WordPress plugin to version 4.9.17 or later.
- Disable the unfiltered_html option in the plugin settings.
- Implement input sanitization and output escaping measures to prevent XSS attacks.
- Regularly monitor for suspicious activity and apply security patches promptly.
Additional Information:
If users have additional queries regarding this incident, they can use the 'Ask to Analyst' feature, contact SOCRadar directly, or open a support ticket for more information if necessary.
Indicators of Compromise
Exploits
News
Social Media
Affected Software
References
CWE Details
CVE Radar
Real-time CVE Intelligence & Vulnerability Management Platform
CVE Radar provides comprehensive vulnerability intelligence by monitoring CVE databases, security advisories, and threat feeds. Get instant updates on new vulnerabilities, exploit details, and mitigation strategies specific to your assets.