PT-2024-34823 · Marcel Pol · Elo Rating Shortcode

Theviper17

·

Published

2024-11-04

·

Updated

2024-11-07

·

CVE-2024-51678

CVSS v3.1

6.5

Medium

VectorAV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L
Name of the Vulnerable Software and Affected Versions Elo Rating Shortcode versions 1.0.3 and earlier Elo Rating Shortcode versions prior to 1.0.4
Description The issue is related to Improper Neutralization of Input During Web Page Generation, also known as Cross-site Scripting (XSS). This allows for Stored XSS attacks. The vulnerability exists in the Elo Rating Shortcode by Marcel Pol.
Recommendations For Elo Rating Shortcode versions 1.0.3 and earlier, update to version 1.0.4 or later to resolve the issue. For Elo Rating Shortcode versions prior to 1.0.4, update to version 1.0.4 or later to resolve the issue. As a temporary workaround, consider disabling the vulnerable Elo Rating Shortcode function until a patch is available.

Fix

XSS

Weakness Enumeration

Related Identifiers

CVE-2024-51678

Affected Products

Elo Rating Shortcode