CVE-2024-4635: Menu Icons by ThemeIsle <= 0.13.13 - Authenticated (Author+) Stored Cross-Site Scripting via SVG Upload
The Menu Icons by ThemeIsle plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘addmimetype’ function in versions up to, and including, 0.13.13 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with author-level permissions and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-4635?
CVE-2024-4635 is classified as a high-severity vulnerability due to its potential for exploitation via Stored Cross-Site Scripting.
How do I fix CVE-2024-4635?
To fix CVE-2024-4635, update the Menu Icons by ThemeIsle plugin to version 0.13.14 or later.
Who is affected by CVE-2024-4635?
CVE-2024-4635 affects users of the Menu Icons by ThemeIsle plugin for WordPress versions up to and including 0.13.13.
What type of vulnerability is CVE-2024-4635?
CVE-2024-4635 is a Stored Cross-Site Scripting (XSS) vulnerability caused by insufficient input sanitization and output escaping.
Are there any known exploits for CVE-2024-4635?
Yes, CVE-2024-4635 can be exploited by authenticated attackers to execute arbitrary scripts in a user's browser.