CVE-2024-5074: WP eMember < 10.6.6 - Reflected XSS
The wp-eMember WordPress plugin before 10.6.6 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-5074?
CVE-2024-5074 has a severity rating that indicates a critical vulnerability due to its potential for Reflected Cross-Site Scripting affecting high privilege users.
How do I fix CVE-2024-5074?
To fix CVE-2024-5074, update the WP eMember WordPress plugin to version 10.6.6 or later.
Who is affected by CVE-2024-5074?
CVE-2024-5074 affects users of the WP eMember WordPress plugin prior to version 10.6.6.
What type of vulnerability is CVE-2024-5074?
CVE-2024-5074 is classified as a Reflected Cross-Site Scripting vulnerability.
What can attackers do with CVE-2024-5074?
Attackers can exploit CVE-2024-5074 to execute scripts in the context of high privilege users, such as administrators.