CVE-2024-10515: SEO Plugin by Squirrly SEO < 12.3.21 - Editor+ Stored XSS
Published Nov 20, 2024
·Updated
In the process of testing the SEO Plugin by Squirrly SEO WordPress plugin before 12.3.21, a vulnerability was found that allows you to implement Stored XSS on behalf of the editor by embedding malicious script, which entails account takeover backdoor
Affected Software
2 affected components
Squirrly SEO SEO Plugin<12.3.21
Squirrly SEO Plugin by Squirrly SEO WordPress<12.3.21
Event History
Nov 20, 2024
CVE Published
via MITRE·06:00 AM
Data Sourced
via MITRE·06:00 AM
DescriptionWeakness
Data Sourced
via NVD·06:15 AM
DescriptionSeverity
Frequently Asked Questions
1
What is the severity of CVE-2024-10515?
CVE-2024-10515 is a critical vulnerability that allows for Stored XSS attacks and potential account takeover.
2
How do I fix CVE-2024-10515?
To fix CVE-2024-10515, upgrade the Squirrly SEO WordPress plugin to version 12.3.21 or later.
3
Which versions of Squirrly SEO are affected by CVE-2024-10515?
CVE-2024-10515 affects all versions of the Squirrly SEO plugin prior to 12.3.21.
4
What type of vulnerability is CVE-2024-10515?
CVE-2024-10515 is a Stored Cross-Site Scripting (XSS) vulnerability.
5
Can CVE-2024-10515 lead to data breaches?
Yes, CVE-2024-10515 can allow attackers to execute scripts, potentially leading to account takeover and data breaches.