CVE-2024-10815: PostLists <= 2.0.2 - Reflected XSS
Published Jan 9, 2025
·Updated
The PostLists WordPress plugin through 2.0.2 does not escape the $SERVER['REQUESTURI'] parameter before outputting it back in an attribute, which could lead to Reflected Cross-Site Scripting in old web browsers
Affected Software
2 affected components
Reneade Postlists Wordpress<=2.0.2
PostLists PostLists WordPress plugin<=2.0.2
Event History
Jan 9, 2025
CVE Published
via MITRE·06:00 AM
Data Sourced
via MITRE·06:00 AM
DescriptionWeakness
Data Sourced
via NVD·06:15 AM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2024-10815?
CVE-2024-10815 has been classified as a medium severity vulnerability.
2
How do I fix CVE-2024-10815?
To mitigate CVE-2024-10815, update the PostLists WordPress plugin to a version higher than 2.0.2.
3
What type of vulnerability is CVE-2024-10815?
CVE-2024-10815 is a Reflected Cross-Site Scripting (XSS) vulnerability.
4
Which versions of the PostLists WordPress plugin are affected by CVE-2024-10815?
Versions of the PostLists WordPress plugin up to and including 2.0.2 are affected by CVE-2024-10815.
5
What can an attacker do with CVE-2024-10815?
An attacker could exploit CVE-2024-10815 to execute arbitrary JavaScript code in the context of a user's browser.