CVE-2024-0255: WP Recipe Maker <= 9.1.0 - Authenticated (Contributor+) Stored Cross-Site Scripting via icon_color
The WP Recipe Maker plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'wprm-recipe-text-share' shortcode in all versions up to, and including, 9.1.0 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers with contributor-level and above permissions to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2024-0255?
The severity of CVE-2024-0255 is considered medium due to its potential for attacking users via Stored Cross-Site Scripting.
How do I fix CVE-2024-0255?
To fix CVE-2024-0255, you should update the WP Recipe Maker plugin to version 9.2.0 or later as it addresses the vulnerability.
What versions of WP Recipe Maker are affected by CVE-2024-0255?
All versions of the WP Recipe Maker plugin prior to version 9.2.0 are affected by CVE-2024-0255.
What impact does CVE-2024-0255 have on users?
CVE-2024-0255 can allow attackers to inject malicious scripts into web pages viewed by other users, potentially compromising user data.
Is there a workaround for CVE-2024-0255 if I cannot update immediately?
There is no official workaround for CVE-2024-0255, thus immediate upgrade is recommended to mitigate risk.