CVE-2024-5280: WP Affiliate Platform < 6.5.1 - POST Reflected XSS
Published Jul 13, 2024
·Updated
The wp-affiliate-platform WordPress plugin before 6.5.1 does not have CSRF check in some places, and is missing sanitisation as well as escaping, which could allow attackers to make non-logged in users execute an XSS payload via a CSRF attack
Affected Software
2 affected components
Tipsandtricks-hq Wp Affiliate Platform Wordpress<6.5.1
WP Affiliate Platform WP Affiliate Platform<6.5.1
Event History
Jul 13, 2024
CVE Published
via MITRE·06:00 AM
Data Sourced
via MITRE·06:00 AM
DescriptionWeakness
Data Sourced
via NVD·06:15 AM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2024-5280?
The severity of CVE-2024-5280 is rated as high due to the potential for XSS attacks via CSRF exploitation.
2
How do I fix CVE-2024-5280?
To fix CVE-2024-5280, update the WP Affiliate Platform plugin to version 6.5.1 or later.
3
Who is affected by CVE-2024-5280?
CVE-2024-5280 affects users of the WP Affiliate Platform plugin prior to version 6.5.1.
4
What type of attack does CVE-2024-5280 enable?
CVE-2024-5280 enables cross-site scripting (XSS) attacks through exploitations of a cross-site request forgery (CSRF) vulnerability.
5
Is authentication required to exploit CVE-2024-5280?
No, CVE-2024-5280 can be exploited by non-logged in users, making it more dangerous.