CVE-2024-5079: WP eMember < 10.6.7 - Unauthenticated Stored XSS via Member Registration
Published Jul 13, 2024
·Updated
The wp-eMember WordPress plugin before 10.6.7 does not sanitise and escape some of the fields when members register, which allows unauthenticated users to perform Stored Cross-Site Scripting attacks
Affected Software
2 affected components
Tipsandtricks-hq Wp Emember Wordpress<10.6.7
WordPress wp-eMember<10.6.7
Event History
Jul 13, 2024
CVE Published
via MITRE·06:00 AM
Data Sourced
via MITRE·06:00 AM
DescriptionWeakness
Data Sourced
via NVD·06:15 AM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2024-5079?
CVE-2024-5079 is considered to have a high severity due to its potential for Stored Cross-Site Scripting attacks.
2
How do I fix CVE-2024-5079?
To fix CVE-2024-5079, update the wp-eMember plugin to version 10.6.7 or later.
3
What types of attacks does CVE-2024-5079 allow?
CVE-2024-5079 allows unauthenticated users to perform Stored Cross-Site Scripting attacks.
4
Which versions of wp-eMember are affected by CVE-2024-5079?
CVE-2024-5079 affects wp-eMember versions prior to 10.6.7.
5
What is the impact of CVE-2024-5079 on websites using wp-eMember?
The impact of CVE-2024-5079 on websites includes potential unauthorized access and exploitation through Stored Cross-Site Scripting.