The Floating Contact Button WordPress plugin before 2.8 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Cross-Site Scripting attacks even when unfiltered_html is disallowed
History

Thu, 12 Sep 2024 20:30:00 +0000

Type Values Removed Values Added
First Time appeared Christoph Nagel
Christoph Nagel floating Contact Button
CPEs cpe:2.3:a:christoph_nagel:floating_contact_button:*:*:*:*:*:*:*:*
Vendors & Products Christoph Nagel
Christoph Nagel floating Contact Button
Metrics cvssV3_1

{'score': 4.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 10 Sep 2024 06:15:00 +0000

Type Values Removed Values Added
Description The Floating Contact Button WordPress plugin before 2.8 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Cross-Site Scripting attacks even when unfiltered_html is disallowed
Title Floating Contact Button < 2.8 - Admin+ Stored XSS
References

cve-icon MITRE

Status: PUBLISHED

Assigner: WPScan

Published: 2024-09-10T06:00:01.694Z

Updated: 2024-09-12T20:04:55.772Z

Reserved: 2024-08-16T17:41:31.240Z

Link: CVE-2024-7891

cve-icon Vulnrichment

Updated: 2024-09-12T20:04:49.257Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2024-09-10T06:15:02.633

Modified: 2024-09-12T20:35:27.267

Link: CVE-2024-7891

cve-icon Redhat

No data.