PT-2024-28598 · WordPress · Pray For Me

Bob Matyas

·

Published

2024-06-14

·

Updated

2024-10-28

·

CVE-2024-3966

CVSS v3.1

6.1

Medium

VectorAV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions Pray For Me WordPress plugin versions 1.0.0 through 1.0.4
Description The issue allows unauthenticated visitors to perform Cross-Site Scripting attacks that trigger when an admin visits the Prayer Requests in the WP Admin. This is due to the plugin not sanitising and escaping some parameters.
Recommendations For Pray For Me WordPress plugin versions 1.0.0 through 1.0.4, update to a version that addresses the sanitisation and escaping of parameters to prevent Cross-Site Scripting attacks. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

XSS

Weakness Enumeration

Related Identifiers

CVE-2024-3966

Affected Products

Pray For Me