PT-2024-19269 · WordPress · Button Contact Vr Wordpress Plugin

Dmitry Ignatyev

·

Published

2024-05-23

·

Updated

2025-05-15

·

CVE-2024-2220

CVSS v3.1

3.5

Low

VectorAV:N/AC:L/PR:H/UI:R/S:U/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions The Button contact VR WordPress plugin versions through 4.7
Description The issue allows high privilege users, such as admins, to perform Stored Cross-Site Scripting attacks. This is possible because some settings are not properly sanitised and escaped, and this issue can be exploited even when the unfiltered html capability is disallowed, for example in a multisite setup.
Recommendations For versions through 4.7, as a temporary workaround, consider restricting access to the plugin's settings to minimize the risk of exploitation. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

XSS

Weakness Enumeration

Related Identifiers

CVE-2024-2220

Affected Products

Button Contact Vr Wordpress Plugin