CVE-2024-0559: Enhanced Text Widget < 1.6.6 - Admin+ Stored XSS
The Enhanced Text Widget WordPress plugin before 1.6.6 does not validate and escape some of its Widget options before outputting them back in attributes, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfilteredhtml capability is disallowed (for example in multisite setup)
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-0559?
The severity of CVE-2024-0559 is considered high due to the potential for Stored Cross-Site Scripting attacks.
How do I fix CVE-2024-0559?
To fix CVE-2024-0559, update the Enhanced Text Widget plugin to version 1.6.6 or later.
Who is impacted by CVE-2024-0559?
CVE-2024-0559 impacts WordPress sites using the Enhanced Text Widget plugin before version 1.6.6, particularly affecting high privilege users such as administrators.
What type of attack can be executed due to CVE-2024-0559?
CVE-2024-0559 can allow attackers to execute Stored Cross-Site Scripting attacks.
Is user input validated in the Enhanced Text Widget plugin affected by CVE-2024-0559?
No, the Enhanced Text Widget plugin does not properly validate and escape some of its Widget options, leaving it vulnerable to attacks.