The Curator.io: Show all your social media posts in a beautiful feed. plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘feed_id’ attribute in all versions up to, and including, 1.9 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
Metrics
Affected Vendors & Products
References
History
Tue, 15 Oct 2024 14:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
First Time appeared |
Curator
Curator curator.io |
|
CPEs | cpe:2.3:a:curator:curator.io:*:*:*:*:*:wordpress:*:* | |
Vendors & Products |
Curator
Curator curator.io |
Thu, 10 Oct 2024 14:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Metrics |
ssvc
|
Thu, 10 Oct 2024 02:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | The Curator.io: Show all your social media posts in a beautiful feed. plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘feed_id’ attribute in all versions up to, and including, 1.9 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. | |
Title | Curator.io: Show all your social media posts in a beautiful feed. <= 1.9 - Authenticated (Contributor+) Stored Cross-Site Scripting via feed_id Attribute | |
Weaknesses | CWE-79 | |
References |
| |
Metrics |
cvssV3_1
|
MITRE
Status: PUBLISHED
Assigner: Wordfence
Published: 2024-10-10T02:06:09.939Z
Updated: 2024-10-10T13:12:15.053Z
Reserved: 2024-09-20T20:06:30.807Z
Link: CVE-2024-9057
Vulnrichment
Updated: 2024-10-10T13:12:04.821Z
NVD
Status : Analyzed
Published: 2024-10-10T02:15:03.960
Modified: 2024-10-15T13:58:19.960
Link: CVE-2024-9057
Redhat
No data.