CVE-2024-1273: Starbox < 3.5.0 - Contributor+ Stored XSS
The Starbox WordPress plugin before 3.5.0 does not sanitise and escape some parameters, which could allow users with a role as low as Contributor to perform Cross-Site Scripting attacks
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-1273?
CVE-2024-1273 is classified as a medium severity vulnerability due to its potential for Cross-Site Scripting attacks.
How do I fix CVE-2024-1273?
To fix CVE-2024-1273, update the Starbox WordPress plugin to version 3.5.0 or later.
Who is affected by CVE-2024-1273?
Users of the Starbox WordPress plugin versions prior to 3.5.0, particularly those with Contributor roles, are affected by CVE-2024-1273.
What type of attack can CVE-2024-1273 facilitate?
CVE-2024-1273 can facilitate Cross-Site Scripting (XSS) attacks, allowing malicious scripts to be injected into web pages viewed by other users.
Is CVE-2024-1273 considered a low-risk issue?
Due to the ability for low-level users to exploit this vulnerability, CVE-2024-1273 is not considered a low-risk issue.