PT-2024-28436 · WordPress · Cooked+1
Published
2024-07-01
·
Updated
2024-07-02
·
CVE-2024-39310
CVSS v3.1
5.4
Medium
| Vector | AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
The Basil recipe theme for WordPress versions up to, and including, 2.0.4
Description
The issue is related to Persistent Cross-Site Scripting (XSS) via the
post title parameter due to insufficient input sanitization and output escaping. This allows authenticated attackers with contributor-level access and above to inject arbitrary web scripts in pages that will execute whenever a user accesses a compromised page. The default WordPress validation prevents direct payload insertion, but if the Cooked plugin is installed, attackers can create a recipe post type and inject the payload in the title field.Recommendations
For versions up to, and including, 2.0.4, update to version 2.0.5 to resolve the issue.
Fix
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Basil
Cooked