CVE-2024-2732: Themify Shortcodes <= 2.0.8 - Authenticated (Contributor+) Stored Cross-Site Scripting
The Themify Shortcodes plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'themifypostslider shortcode in all versions up to, and including, 2.0.8 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2024-2732?
CVE-2024-2732 has a medium severity rating due to its potential for stored cross-site scripting attacks.
How do I fix CVE-2024-2732?
To fix CVE-2024-2732, update the Themify Shortcodes plugin to version 2.0.9 or later.
What versions are affected by CVE-2024-2732?
CVE-2024-2732 affects all versions of the Themify Shortcodes plugin up to and including version 2.0.8.
What is stored cross-site scripting in the context of CVE-2024-2732?
Stored cross-site scripting in CVE-2024-2732 refers to an attacker being able to inject malicious scripts into the plugin's slider shortcode, which can execute when other users view the affected page.
Who is vulnerable to CVE-2024-2732?
Any WordPress site using the Themify Shortcodes plugin version 2.0.8 or earlier is vulnerable to CVE-2024-2732.