PT-2024-37866 · WordPress · Wp Ulike

Stealthcopter

·

Published

2024-09-05

·

Updated

2024-09-06

·

CVE-2024-6792

CVSS v3.1

3.5

Low

VectorAV:N/AC:L/PR:H/UI:R/S:U/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions WP ULike versions prior to 4.7.2.1
Description The issue arises from the WP ULike WordPress plugin's failure to properly sanitize user display names when rendering them on a public page. This can lead to potential security risks, including the possibility of attackers injecting malicious scripts.
Recommendations For versions prior to 4.7.2.1, update to version 4.7.2.1 or later to resolve the issue. As a temporary workaround, consider restricting the display of user-generated content on public pages until the update is applied.

Exploit

Fix

XSS

Weakness Enumeration

Related Identifiers

CVE-2024-6792

Affected Products

Wp Ulike