PT-2024-22444 · WordPress · Visual Footer Credit Remover
1337_Wannabe
+1
·
Published
2024-05-09
·
Updated
2024-05-14
·
CVE-2024-2846
CVSS v3.1
4.4
Medium
| Vector | AV:N/AC:H/PR:H/UI:N/S:C/C:L/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
Visual Footer Credit Remover plugin for WordPress versions up to, and including, 2
Description
The issue allows authenticated attackers with administrator-level access to inject arbitrary web scripts in pages via the
selector parameter due to insufficient input sanitization and output escaping. This makes it possible for injected scripts to execute whenever a user accesses an injected page. The issue only affects multi-site installations and installations where unfiltered html has been disabled.Recommendations
For Visual Footer Credit Remover plugin for WordPress versions up to, and including, 2, consider disabling the plugin until a patch is available to prevent exploitation. Restrict access to the
selector parameter to minimize the risk of arbitrary web script injection. Avoid using the selector parameter in affected pages until the issue is resolved. At the moment, there is no information about a newer version that contains a fix for this vulnerability.XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Visual Footer Credit Remover