ZeroHour

CVE-2024-0852

PoC
CVSS 3.1
8.8 high
EPSS
<1%p50
Published
()
Modified
Description

The coreActivity: Activity Logging for WordPress plugin before 1.8.1 does not escape some request data when outputting it back in the admin dashboard, allowing unauthenticated users to perform Stored XSS attack against high privilege users such as admin

Vendors
dev4press
Products
coreactivity
Ecosystems
WordPress
Weakness
CWE-79
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.