PT-2024-28622 · WordPress · Cooked

Iamr3N0

+1

·

Published

2024-07-17

·

Updated

2024-07-18

·

CVE-2024-39682

CVSS v3.1

6.4

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:C/C:N/I:L/A:L
Name of the Vulnerable Software and Affected Versions Cooked plugin for WordPress versions up to, and including, 1.7.15.4
Description The Cooked plugin for WordPress is vulnerable to HTML Injection due to insufficient input sanitization and output escaping. This issue allows authenticated attackers with contributor-level access and above to inject arbitrary HTML in pages that will be shown whenever a user accesses a compromised page.
Recommendations For versions up to, and including, 1.7.15.4, upgrade to release version 1.8.0 to address the issue.

Exploit

Fix

Improper Encoding or Escaping of Output

XSS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2024-39682
GHSA-FX69-F77X-84GR

Affected Products

Cooked