ZeroHour

CVE-2024-10103

PoC
CVSS 3.1
6.1 medium
EPSS
<1%p28
Published
()
Modified
Description

In the process of testing the MailPoet WordPress plugin before 5.3.2, a vulnerability was found that allows you to implement Stored XSS on behalf of the editor by embedding malicious script, which entails account takeover backdoor

Vendors
automattic
Products
mailpoet
Ecosystems
WordPress
Weakness
CWE-79
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N

In the news

No ingested article mentions this CVE yet.