CVE-2024-10103: MailPoet < 5.3.2 - Admin+ Stored XSS
Published Nov 19, 2024
·Updated
In the process of testing the MailPoet WordPress plugin before 5.3.2, a vulnerability was found that allows you to implement Stored XSS on behalf of the editor by embedding malicious script, which entails account takeover backdoor
Affected Software
2 affected components
MailPoet MailPoet<5.3.2
Automattic Mailpoet Wordpress<5.3.2
Event History
Nov 19, 2024
CVE Published
via MITRE·06:00 AM
Data Sourced
via MITRE·06:00 AM
DescriptionWeakness
Data Sourced
via NVD·06:15 AM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2024-10103?
CVE-2024-10103 is classified as a high severity vulnerability due to its ability to allow Stored XSS and potential account takeover.
2
How do I fix CVE-2024-10103?
To mitigate CVE-2024-10103, update the MailPoet plugin to version 5.3.2 or later.
3
What type of vulnerability is CVE-2024-10103?
CVE-2024-10103 is a Stored Cross-Site Scripting (XSS) vulnerability that affects the MailPoet WordPress plugin.
4
Who is affected by CVE-2024-10103?
Users of the MailPoet plugin prior to version 5.3.2 are affected by CVE-2024-10103.
5
What can happen if CVE-2024-10103 is exploited?
Exploitation of CVE-2024-10103 may lead to account takeover through the execution of malicious scripts.