CVE-2024-12283: WP Pipes <= 1.4.1 - Reflected Cross-Site Scripting via x1 Parameter
The WP Pipes plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘x1’ parameter in all versions up to, and including, 1.4.1 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a link.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2024-12283?
The vulnerability CVE-2024-12283 is rated as a high severity issue due to the potential for unauthenticated attackers to execute arbitrary scripts.
How do I fix CVE-2024-12283?
To fix CVE-2024-12283, you should update the WP Pipes plugin to version 1.4.2 or greater where the vulnerability has been addressed.
What versions are affected by CVE-2024-12283?
CVE-2024-12283 affects all versions of the WP Pipes plugin up to and including version 1.4.1.
What type of vulnerability is CVE-2024-12283?
CVE-2024-12283 is a Reflected Cross-Site Scripting (XSS) vulnerability caused by insufficient input sanitization.
Who can exploit CVE-2024-12283?
CVE-2024-12283 can be exploited by unauthenticated attackers, making it a significant threat to websites using the affected plugin.