ZeroHour

CVE-2024-10515

PoC
CVSS 3.1
3.5 low
EPSS
<1%p24
Published
()
Modified
Description

In the process of testing the SEO Plugin by Squirrly SEO WordPress plugin before 12.3.21, a vulnerability was found that allows you to implement Stored XSS on behalf of the editor by embedding malicious script, which entails account takeover backdoor

Vendors
squirrly
Products
seo plugin by squirrly seo
Ecosystems
WordPress
Weakness
CWE-79
Vector
CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:U/C:L/I:L/A:N

In the news

No ingested article mentions this CVE yet.