PT-2024-28622 · WordPress · Cooked
Iamr3N0
+1
·
Published
2024-07-17
·
Updated
2024-07-18
·
CVE-2024-39682
CVSS v3.1
6.4
Medium
| Vector | AV:N/AC:L/PR:L/UI:N/S:C/C:N/I:L/A:L |
Name of the Vulnerable Software and Affected Versions
Cooked plugin for WordPress versions up to, and including, 1.7.15.4
Description
The Cooked plugin for WordPress is vulnerable to HTML Injection due to insufficient input sanitization and output escaping. This issue allows authenticated attackers with contributor-level access and above to inject arbitrary HTML in pages that will be shown whenever a user accesses a compromised page.
Recommendations
For versions up to, and including, 1.7.15.4, upgrade to release version 1.8.0 to address the issue.
Exploit
Fix
Improper Encoding or Escaping of Output
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Cooked