CVE-2024-2500: ColorMag <= 3.1.6 - Authenticated (Contributor+) Stored Cross-Site Scripting via Display Name
The ColorMag theme for WordPress is vulnerable to Stored Cross-Site Scripting via a user's Display Name in all versions up to, and including, 3.1.6 due to insufficient input sanitization and output escaping. This makes it possible for authentciated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-2500?
The severity of CVE-2024-2500 is considered medium due to its potential impact on authenticated users.
How do I fix CVE-2024-2500?
To fix CVE-2024-2500, update the ColorMag theme for WordPress to version 3.1.7 or later.
Who is affected by CVE-2024-2500?
CVE-2024-2500 affects all users of the ColorMag theme for WordPress versions up to and including 3.1.6.
What type of vulnerability is CVE-2024-2500?
CVE-2024-2500 is a Stored Cross-Site Scripting (XSS) vulnerability.
Can anonymous users exploit CVE-2024-2500?
No, only authenticated users with contributor-level access and above can exploit CVE-2024-2500.