PT-2024-38100 · WordPress · Liquidpoll

D.Sim

+1

·

Published

2024-08-20

·

Updated

2024-08-25

·

CVE-2024-7134

CVSS v3.1

7.2

High

VectorAV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions LiquidPoll – Polls, Surveys, NPS and Feedback Reviews plugin for WordPress versions up to, and including, 3.3.78
Description The issue is related to Stored Cross-Site Scripting via the form data parameter due to insufficient input sanitization and output escaping. This allows unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
Recommendations For versions up to, and including, 3.3.78, consider disabling the form data parameter until a patch is available to prevent exploitation. Restrict access to pages that may have been injected with malicious scripts to minimize the risk of execution. Update to a version later than 3.3.78 when available, as it is expected to include fixes for the insufficient input sanitization and output escaping.

Fix

XSS

Weakness Enumeration

Related Identifiers

CVE-2024-7134

Affected Products

Liquidpoll