CVE-2024-1384: Premium Portfolio Features for Phlox theme <= 2.3.4 - Authenticated (Contributor+) Stored Cross-Site Scripting
The Premium Portfolio Features for Phlox theme plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'auxrecentportfoliosgrid' shortcode in all versions up to, and including, 2.3.4 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers with contributor-level and above permissions to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-1384?
CVE-2024-1384 is considered a high severity vulnerability due to its potential impact on user data.
How do I fix CVE-2024-1384?
To fix CVE-2024-1384, update the Phlox theme plugin for WordPress to version 2.3.4 or later.
What types of attacks can exploit CVE-2024-1384?
CVE-2024-1384 can be exploited through Stored Cross-Site Scripting attacks.
Which versions of the Phlox theme plugin are affected by CVE-2024-1384?
All versions of the Phlox theme plugin for WordPress up to and including 2.3.3 are affected by CVE-2024-1384.
Is user data at risk due to CVE-2024-1384?
Yes, CVE-2024-1384 poses a risk to user data by potentially allowing attackers to inject malicious scripts.