CVE-2024-11898: Scratch & Win – Giveaways and Contests <= 2.6.9 - Authenticated (Contributor+) Stored Cross-Site Scripting
The Scratch & Win – Giveaways and Contests. Boost subscribers, traffic, repeat visits, referrals, sales and more plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'swin-campaign' shortcode in all versions up to, and including, 2.6.9 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2024-11898?
CVE-2024-11898 has a severity rating that classifies it as a Stored Cross-Site Scripting vulnerability.
How do I fix CVE-2024-11898?
To fix CVE-2024-11898, update the Scratch & Win Giveaways and Contests plugin to version 2.6.10 or higher.
Which versions are affected by CVE-2024-11898?
CVE-2024-11898 affects all versions of the Scratch & Win Giveaways and Contests plugin up to and including version 2.6.9.
What impact does CVE-2024-11898 have?
CVE-2024-11898 allows attackers to inject malicious scripts via the 'swin-campaign' shortcode, potentially leading to unauthorized actions on behalf of users.
Is user data at risk with CVE-2024-11898?
Yes, user data can be at risk due to stored Cross-Site Scripting, which may compromise user sessions and sensitive information.