CVE-2024-12290: Infility Global <= 2.9.8 - Reflected Cross-Site Scripting via set_type Parameter
The Infility Global plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘settype’ parameter in all versions up to, and including, 2.9.8 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a link. CVE-2024-12723 is a duplicate of this issue.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-12290?
CVE-2024-12290 has been classified as a high severity vulnerability due to its potential impact on WordPress sites.
How do I fix CVE-2024-12290?
To fix CVE-2024-12290, you should update the Infility Global plugin to version 2.9.9 or later, which addresses the reflected cross-site scripting vulnerability.
Who is affected by CVE-2024-12290?
CVE-2024-12290 affects all versions of the Infility Global plugin up to and including version 2.9.8.
What type of vulnerability is CVE-2024-12290?
CVE-2024-12290 is a Reflected Cross-Site Scripting (XSS) vulnerability.
Can CVE-2024-12290 be exploited by unauthenticated users?
Yes, CVE-2024-12290 can be exploited by unauthenticated attackers due to insufficient input sanitization.