PT-2024-37763 · WordPress · Master Currency Wp

Artem Polynko

·

Published

2024-07-27

·

Updated

2024-07-29

·

CVE-2024-6634

CVSS v3.1

6.4

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions Master Currency WP plugin versions up to, and including, 1.1.61
Description The issue arises from insufficient input sanitization and output escaping on user-supplied attributes in the currencyconverterform shortcode. This allows authenticated attackers with contributor-level access and above to inject arbitrary web scripts in pages, which will execute when a user accesses an injected page.
Recommendations For Master Currency WP plugin versions up to, and including, 1.1.61, update to a version that addresses the insufficient input sanitization and output escaping issue in the currencyconverterform shortcode. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

XSS

Weakness Enumeration

Related Identifiers

CVE-2024-6634

Affected Products

Master Currency Wp