No analysis available yet.
No remediation available yet.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2024-50943 | ** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2024-54288. Reason: This candidate is a reservation duplicate of CVE-2024-54288. Notes: All CVE users should reference CVE-2024-54288 instead of this candidate. All references and descriptions in this candidate have been removed to prevent accidental usage. |
No reference.
Fri, 17 Jan 2025 17:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | CWE-79 | |
| References |
|
|
| Metrics |
cvssV3_1
|
Fri, 17 Jan 2025 17:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | LDD Directory Lite <= 3.3 - Reflected Cross-Site Scripting via remove_query_arg Parameter | |
| Metrics |
ssvc
|
Fri, 17 Jan 2025 17:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | The LDD Directory Lite plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of remove_query_arg without appropriate escaping on the URL in all versions up to, and including, 3.3. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a link. | ** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2024-54288. Reason: This candidate is a reservation duplicate of CVE-2024-54288. Notes: All CVE users should reference CVE-2024-54288 instead of this candidate. All references and descriptions in this candidate have been removed to prevent accidental usage. |
Tue, 07 Jan 2025 17:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Tue, 07 Jan 2025 03:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | The LDD Directory Lite plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of remove_query_arg without appropriate escaping on the URL in all versions up to, and including, 3.3. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a link. | |
| Title | LDD Directory Lite <= 3.3 - Reflected Cross-Site Scripting via remove_query_arg Parameter | |
| Weaknesses | CWE-79 | |
| References |
| |
| Metrics |
cvssV3_1
|
Subscriptions
No data.
Status: REJECTED
Assigner: Wordfence
Published:
Updated: 2025-01-17T16:45:24.984Z
Reserved: 2024-12-11T20:18:22.935Z
Link: CVE-2024-12540
Updated:
Status : Rejected
Published: 2025-01-07T04:15:08.917
Modified: 2025-01-17T17:15:10.807
Link: CVE-2024-12540
No data.
OpenCVE Enrichment
No data.
No weakness.
EUVD