CVE-2024-3867: Tainacan Interface <= 2.7.2 - Reflected Cross-Site Scripting
The archive-tainacan-collection theme for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of addqueryarg without appropriate escaping on the URL in version 2.7.2. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a link.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-3867?
CVE-2024-3867 has a medium severity rating due to its potential for Reflected Cross-Site Scripting attacks.
How do I fix CVE-2024-3867?
To fix CVE-2024-3867, update the archive-tainacan-collection theme to the latest version that contains the patched code.
What systems are affected by CVE-2024-3867?
CVE-2024-3867 affects the archive-tainacan-collection theme for WordPress version 2.7.2.
Can unauthenticated users exploit CVE-2024-3867?
Yes, unauthenticated attackers can exploit CVE-2024-3867 to inject arbitrary web scripts.
What is Reflected Cross-Site Scripting as related to CVE-2024-3867?
Reflected Cross-Site Scripting in CVE-2024-3867 refers to the vulnerability allowing attackers to execute malicious scripts in the context of a user's browser.