PT-2024-37928 · WordPress · Giveaways/Contests By Rafflepress

Dmitry Ignatyev

·

Published

2024-09-11

·

Updated

2024-09-26

·

CVE-2024-6887

CVSS v3.1

4.8

Medium

VectorAV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions Giveaways and Contests by RafflePress WordPress plugin versions prior to 1.12.16
Description The issue concerns the Giveaways and Contests by RafflePress WordPress plugin, which does not properly sanitise and escape some of its Giveaways settings. This could allow high privilege users, such as editors and above, to perform Stored Cross-Site Scripting attacks, even when the unfiltered html capability is disallowed, for example in multisite setups.
Recommendations For versions prior to 1.12.16, update to version 1.12.16 or later to resolve the issue. As a temporary workaround, consider restricting access to the Giveaways settings to minimize the risk of exploitation. Additionally, restrict the capability to edit Giveaways settings to only the most trusted users, such as administrators.

Exploit

Fix

XSS

Weakness Enumeration

Related Identifiers

CVE-2024-6887

Affected Products

Giveaways/Contests By Rafflepress