CVE-2024-2872: Swift Framework < 2024.04.30 - Contributor+ Stored XSS
The socialdriver-framework WordPress plugin before 2024.04.30 does not sanitise and escape some of its settings, which could allow high privilege users such as contributor to perform Stored Cross-Site Scripting attacks even when the unfilteredhtml capability is disallowed (for example in multisite setup)
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-2872?
CVE-2024-2872 is considered a moderate severity vulnerability due to its potential for Stored Cross-Site Scripting attacks.
How do I fix CVE-2024-2872?
To fix CVE-2024-2872, update the socialdriver-framework WordPress plugin to version 2024.04.30 or later.
Who is affected by CVE-2024-2872?
CVE-2024-2872 affects users of the socialdriver-framework WordPress plugin prior to version 2024.04.30.
What type of vulnerability is CVE-2024-2872?
CVE-2024-2872 is a Stored Cross-Site Scripting (XSS) vulnerability.
Can high privilege users exploit CVE-2024-2872?
Yes, high privilege users such as contributors can exploit CVE-2024-2872 to perform Stored Cross-Site Scripting attacks.