CVE-2024-5075: WP eMember < 10.6.6 - Reflected XSS
Published Jul 13, 2024
·Updated
The wp-eMember WordPress plugin before 10.6.6 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin
Affected Software
2 affected components
WP eMember WP eMember<10.6.6
Tipsandtricks-hq Wp Emember Wordpress<10.6.6
Event History
Jul 13, 2024
CVE Published
via MITRE·06:00 AM
Data Sourced
via MITRE·06:00 AM
DescriptionWeakness
Data Sourced
via NVD·06:15 AM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2024-5075?
The severity of CVE-2024-5075 is classified as high due to its potential impact on high privilege users.
2
How do I fix CVE-2024-5075?
To fix CVE-2024-5075, upgrade the wp-eMember WordPress plugin to version 10.6.6 or later.
3
Who is affected by CVE-2024-5075?
CVE-2024-5075 affects users of the wp-eMember plugin prior to version 10.6.6.
4
What type of vulnerability is CVE-2024-5075?
CVE-2024-5075 is a Reflected Cross-Site Scripting vulnerability.
5
What are the potential consequences of CVE-2024-5075?
The potential consequences include unauthorized execution of scripts in the context of high privilege users, such as admins.