CVE-2024-10107: Giveaways and Contests by RafflePress < 1.12.17 - Admin+ Stored XSS
The Giveaways and Contests by RafflePress WordPress plugin before 1.12.17 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfilteredhtml capability is disallowed (for example in multisite setup).
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-10107?
CVE-2024-10107 is classified as a high severity vulnerability due to its potential for Stored Cross-Site Scripting attacks.
Who is affected by CVE-2024-10107?
CVE-2024-10107 affects users of the Giveaways and Contests by RafflePress plugin versions prior to 1.12.17.
How do I fix CVE-2024-10107?
To fix CVE-2024-10107, you should update the Giveaways and Contests by RafflePress plugin to version 1.12.17 or later.
What kind of attack does CVE-2024-10107 allow?
CVE-2024-10107 allows high privilege users, such as admins, to conduct Stored Cross-Site Scripting attacks.
Is my site still at risk if unfiltered_html capability is disallowed with CVE-2024-10107?
Yes, CVE-2024-10107 can still pose a risk even when the unfiltered_html capability is disallowed.