CVE-2024-4602: Embed Peertube Playlist < 1.10 - Editor+ Stored XSS
The Embed Peertube Playlist WordPress plugin before 1.10 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfilteredhtml capability is disallowed (for example in multisite setup)
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-4602?
CVE-2024-4602 is considered a high-severity vulnerability due to the potential for Stored Cross-Site Scripting attacks.
How do I fix CVE-2024-4602?
To fix CVE-2024-4602, update the Embed Peertube Playlist WordPress plugin to version 1.10 or higher.
Who is affected by CVE-2024-4602?
Users of the Embed Peertube Playlist WordPress plugin below version 1.10 are at risk from CVE-2024-4602.
What kind of attack does CVE-2024-4602 allow?
CVE-2024-4602 allows high privilege users, such as administrators, to perform Stored Cross-Site Scripting attacks.
Is unfiltered_html capability relevant to CVE-2024-4602?
Yes, CVE-2024-4602 can enable attacks even when the unfiltered_html capability is disallowed.