CVE-2024-5077: WP eMember < 10.6.6 - Stored XSS in Blacklist via CSRF
Published Jul 13, 2024
·Updated
The wp-eMember WordPress plugin before 10.6.6 does not have CSRF check in some places, and is missing sanitisation as well as escaping, which could allow attackers to make logged in admin add Stored XSS payloads via a CSRF attack
Affected Software
2 affected components
Tipsandtricks-hq Wp Emember Wordpress<10.6.6
WordPress wp-eMember<10.6.6
Event History
Jul 13, 2024
CVE Published
via MITRE·06:00 AM
Data Sourced
via MITRE·06:00 AM
DescriptionWeakness
Data Sourced
via NVD·06:15 AM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2024-5077?
CVE-2024-5077 has a high severity rating due to the potential for stored cross-site scripting attacks.
2
How do I fix CVE-2024-5077?
To fix CVE-2024-5077, update the wp-eMember plugin to version 10.6.6 or later.
3
What vulnerabilities does CVE-2024-5077 introduce?
CVE-2024-5077 introduces vulnerabilities such as lack of CSRF checks and insufficient sanitization and escaping.
4
Who is affected by CVE-2024-5077?
CVE-2024-5077 affects users of the wp-eMember WordPress plugin prior to version 10.6.6.
5
Can CVE-2024-5077 lead to data theft?
Yes, CVE-2024-5077 can potentially lead to data theft through stored cross-site scripting attacks.