PT-2024-31242 · WordPress · Wp Logs Book

Bob Matyas

·

Published

2024-06-21

·

Updated

2024-07-12

·

CVE-2024-4477

CVSS v3.1

5.4

Medium

VectorAV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions WP Logs Book WordPress plugin versions 1.0.1 and earlier
Description The issue is related to the WP Logs Book WordPress plugin, which does not properly sanitise and escape some of its log data before outputting it back in an admin dashboard. This leads to an Unauthenticated Stored Cross-Site Scripting issue.
Recommendations For WP Logs Book WordPress plugin versions 1.0.1 and earlier, update to a version that properly sanitises and escapes log data to prevent Unauthenticated Stored Cross-Site Scripting. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

XSS

Weakness Enumeration

Related Identifiers

CVE-2024-4477

Affected Products

Wp Logs Book