The Starbox WordPress plugin before 3.5.3 does not properly render social media profiles URLs in certain contexts, like the malicious user's profile or pages where the starbox shortcode is used, which may be abused by users with at least the contributor role to conduct Stored XSS attacks.
Metrics
Affected Vendors & Products
References
History
Mon, 07 Oct 2024 16:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
First Time appeared |
Squirrly
Squirrly starbox |
|
Weaknesses | CWE-79 | |
CPEs | cpe:2.3:a:squirrly:starbox:*:*:*:*:*:wordpress:*:* | |
Vendors & Products |
Squirrly
Squirrly starbox |
Tue, 01 Oct 2024 14:30:00 +0000
Type | Values Removed | Values Added |
---|---|---|
First Time appeared |
Squirrlyuk
Squirrlyuk starbox |
|
CPEs | cpe:2.3:a:squirrlyuk:starbox:*:*:*:*:*:*:*:* | |
Vendors & Products |
Squirrlyuk
Squirrlyuk starbox |
|
Metrics |
cvssV3_1
|
Mon, 30 Sep 2024 06:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | The Starbox WordPress plugin before 3.5.3 does not properly render social media profiles URLs in certain contexts, like the malicious user's profile or pages where the starbox shortcode is used, which may be abused by users with at least the contributor role to conduct Stored XSS attacks. | |
Title | Starbox < 3.5.3 - Contributor+ Stored XSS | |
References |
|
MITRE
Status: PUBLISHED
Assigner: WPScan
Published: 2024-09-30T06:00:06.516Z
Updated: 2024-10-01T13:58:54.159Z
Reserved: 2024-08-27T18:59:09.028Z
Link: CVE-2024-8239
Vulnrichment
Updated: 2024-10-01T13:58:40.692Z
NVD
Status : Analyzed
Published: 2024-09-30T06:15:14.520
Modified: 2024-10-07T15:48:35.887
Link: CVE-2024-8239
Redhat
No data.