CVE-2024-2697: Swift Framework < 2024.0.0 - Contributor+ Stored XSS via Shortcode
The socialdriver-framework WordPress plugin before 2024.0.0 does not validate and escape some of its shortcode attributes before outputting them back in the page, which could allow users with a role as low as contributor to perform Stored Cross-Site Scripting attacks which could be used against high privilege users such as admins.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-2697?
The severity of CVE-2024-2697 is considered medium due to its potential for Stored Cross-Site Scripting attacks.
How do I fix CVE-2024-2697?
To fix CVE-2024-2697, update the Socialdriver Framework WordPress plugin to version 2024.0.0 or later.
Who is affected by CVE-2024-2697?
CVE-2024-2697 affects users of the Socialdriver Framework WordPress plugin versions before 2024.0.0.
What kind of attack does CVE-2024-2697 allow?
CVE-2024-2697 allows users with a role as low as contributor to perform Stored Cross-Site Scripting attacks.
How does CVE-2024-2697 exploit WordPress?
CVE-2024-2697 exploits WordPress by not validating and escaping shortcode attributes before outputting them.