CVE-2024-8787
Zaytech
CVE-2024-8787 is a Cross-Site Scripting (XSS) vulnerability in the Smart Online Order for Clover plugin for WordPress, potentially allowing attackers to inject malicious scripts into websites. This vulnerability exists due to improper handling of URL parameters in versions up to 1.5.7. While the CVSS score is 0, the SVRS score of 30 indicates a moderate risk, suggesting that while not immediately critical, the vulnerability should still be addressed to prevent potential exploitation. An unauthenticated attacker could exploit this WordPress plugin vulnerability by tricking a user into clicking a malicious link, leading to script execution within the user's browser. The lack of escaping in 'add_query_arg' and 'remove_query_arg' functions creates an avenue for attack. This could lead to account compromise, data theft, or website defacement. Although the SVRS is not in the critical range, proactively patching this vulnerability is advisable to secure your WordPress site.
Indicators of Compromise
Exploits
News
Social Media
Affected Software
References
CWE Details
CVE Radar
Real-time CVE Intelligence & Vulnerability Management Platform
CVE Radar provides comprehensive vulnerability intelligence by monitoring CVE databases, security advisories, and threat feeds. Get instant updates on new vulnerabilities, exploit details, and mitigation strategies specific to your assets.