CVE-2024-9892
Arelthiaphillips
CVE-2024-9892: Stored Cross-Site Scripting (XSS) vulnerability in the Add Widget After Content WordPress plugin. The vulnerability affects versions up to 2.4.6, allowing authenticated administrators to inject malicious web scripts into pages. Successful exploitation requires administrator-level access and either a multi-site WordPress installation or the disabling of unfiltered_html. With an SVRS score of 49, the threat is moderate, but remediation is still advised. This could allow attackers to execute arbitrary code in a user's browser when they visit a compromised page. The risk is significant if administrator accounts are compromised or if the targeted WordPress environment meets the required conditions. Immediate patching is recommended to prevent potential account takeover and data theft.
Indicators of Compromise
Exploits
News
Social Media
Affected Software
References
CWE Details
CVE Radar
Real-time CVE Intelligence & Vulnerability Management Platform
CVE Radar provides comprehensive vulnerability intelligence by monitoring CVE databases, security advisories, and threat feeds. Get instant updates on new vulnerabilities, exploit details, and mitigation strategies specific to your assets.