CVE-2024-2857
Simple Buttons Creator <= 1.04 - Unauthenticated Stored XSS
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
1Exploited in Wild
-Decision
Descriptions
The Simple Buttons Creator WordPress plugin through 1.04 does not have any authorisation as well as CSRF in its add button function, allowing unauthenticated users to call them either directly or via CSRF attacks. Furthermore, due to the lack of sanitisation and escaping, it could also allow them to perform Stored Cross-Site Scripting attacks against logged in admins.
El complemento Simple Buttons Creator de WordPress hasta la versión 1.04 no tiene ninguna autorización ni CSRF en su función de agregar botón, lo que permite a usuarios no autenticados llamarlos directamente o mediante ataques CSRF. Además, debido a la falta de sanitización y escape, también podría permitirles realizar ataques de Cross-Site Scripting Almacenado contra administradores que hayan iniciado sesión.
The Simple Buttons Creator plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the "Add Button" functionality in all versions up to, and including, 1.04 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. NOTE: This issue is exploitable as an unauthenticated user, as well as via Cross-Site Request Forgery, due to a lack of authorization and nonce checks, respectively, within the affected function.
CVSS Scores
SSVC
- Decision:Track*
Timeline
- 2024-03-23 CVE Reserved
- 2024-03-25 CVE Published
- 2024-04-15 EPSS Updated
- 2024-08-09 CVE Updated
- 2024-08-09 First Exploit
- ---------- Exploited in Wild
- ---------- KEV Due Date
CWE
- CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CAPEC
References (1)
URL | Tag | Source |
---|
URL | Date | SRC |
---|---|---|
https://wpscan.com/vulnerability/b7a35c5b-474a-444a-85ee-c50782c7a6c2 | 2024-08-09 |
URL | Date | SRC |
---|
URL | Date | SRC |
---|
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Unknown Search vendor "Unknown" | Simple Buttons Creator Search vendor "Unknown" for product "Simple Buttons Creator" | <= 1.04 Search vendor "Unknown" for product "Simple Buttons Creator" and version " <= 1.04" | en |
Affected
|