CVE-2024-2870: Swift Framework < 2024.04.30 - Reflected XSS
The socialdriver-framework WordPress plugin before 2024.04.30 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-2870?
CVE-2024-2870 is considered a high severity vulnerability due to the potential for reflected Cross-Site Scripting attacks targeting high privilege users.
How do I fix CVE-2024-2870?
To fix CVE-2024-2870, update the socialdriver-framework WordPress plugin to version 2024.04.30 or later.
Who is affected by CVE-2024-2870?
CVE-2024-2870 affects users of the socialdriver-framework WordPress plugin prior to version 2024.04.30.
What type of vulnerability is CVE-2024-2870?
CVE-2024-2870 is classified as a Reflected Cross-Site Scripting vulnerability.
Can CVE-2024-2870 be exploited remotely?
Yes, CVE-2024-2870 can potentially be exploited remotely against high privilege users, such as administrators.