The Pocket Widget WordPress plugin through 0.1.3 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).
History

Mon, 09 Sep 2024 14:30:00 +0000

Type Values Removed Values Added
First Time appeared Pocket Widget Wordpress Plugin
Pocket Widget Wordpress Plugin pocket Widget Wordpress Plugin
Weaknesses CWE-79
CPEs cpe:2.3:a:pocket_widget_wordpress_plugin:pocket_widget_wordpress_plugin:*:*:*:*:*:*:*:*
Vendors & Products Pocket Widget Wordpress Plugin
Pocket Widget Wordpress Plugin pocket Widget Wordpress Plugin
Metrics cvssV3_1

{'score': 4.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Mon, 09 Sep 2024 06:15:00 +0000

Type Values Removed Values Added
Description The Pocket Widget WordPress plugin through 0.1.3 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).
Title Pocket Widget <= 0.1.3 - Admin+ Stored XSS
References

cve-icon MITRE

Status: PUBLISHED

Assigner: WPScan

Published: 2024-09-09T06:00:02.962Z

Updated: 2024-09-09T13:13:32.321Z

Reserved: 2024-08-18T16:51:15.982Z

Link: CVE-2024-7918

cve-icon Vulnrichment

Updated: 2024-09-09T13:13:23.002Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2024-09-09T06:15:02.343

Modified: 2024-09-09T14:35:10.777

Link: CVE-2024-7918

cve-icon Redhat

No data.