CVE-2024-37253
WordPress WPDirectoryKit plugin <= 1.3.6 - HTML Injection vulnerability
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
0Exploited in Wild
-Decision
Descriptions
Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection') vulnerability in WpDirectoryKit WP Directory Kit allows Code Injection.This issue affects WP Directory Kit: from n/a through 1.3.6.
Neutralización incorrecta de elementos especiales en la salida utilizados por una vulnerabilidad de componente posterior ("Injection") en WpDirectoryKit WP Directory Kit permite la inyección de código. Este problema afecta a WP Directory Kit: desde n/a hasta 1.3.6.
The WP Directory Kit plugin for WordPress is vulnerable to HTML Injection in all versions up to, and including, 1.3.6. This is due to improper sanitization and escaping on a value. This makes it possible for authenticated attackers, with administrator-level access and above, to inject HTML in a field they should not be able to .
CVSS Scores
SSVC
- Decision:Track
Timeline
- 2024-06-04 CVE Reserved
- 2024-06-26 CVE Published
- 2024-07-10 EPSS Updated
- 2024-08-02 CVE Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
- CWE-74: Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')
CAPEC
- CAPEC-242: Code Injection
References (1)
URL | Tag | Source |
---|---|---|
https://patchstack.com/database/vulnerability/wpdirectorykit/wordpress-wpdirectorykit-plugin-1-3-2-html-injection-vulnerability?_s_id=cve | Vdb Entry |
URL | Date | SRC |
---|
URL | Date | SRC |
---|
URL | Date | SRC |
---|
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Wpdirectorykit Search vendor "Wpdirectorykit" | Wpdirectorykit Search vendor "Wpdirectorykit" for product "Wpdirectorykit" | >= 0.0.0 <= 1.3.6 Search vendor "Wpdirectorykit" for product "Wpdirectorykit" and version " >= 0.0.0 <= 1.3.6" | en |
Affected
|