CVE-2024-5744: WP eMember < 10.6.7 - Reflected XSS
The wp-eMember WordPress plugin before 10.6.7 does not escape the $SERVER['REQUESTURI'] parameter before outputting it back in an attribute, which could lead to Reflected Cross-Site Scripting in old web browsers
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-5744?
CVE-2024-5744 is categorized as a medium severity vulnerability due to its potential for reflected cross-site scripting attacks.
How do I fix CVE-2024-5744?
To resolve CVE-2024-5744, upgrade the WP eMember plugin to version 10.6.7 or later where the issue has been patched.
What types of attacks can CVE-2024-5744 lead to?
CVE-2024-5744 can lead to reflected cross-site scripting attacks, allowing attackers to execute malicious scripts in users' browsers.
Who is affected by CVE-2024-5744?
CVE-2024-5744 affects users of the WP eMember WordPress plugin version prior to 10.6.7.
Is CVE-2024-5744 exploitable in all web browsers?
The exploit for CVE-2024-5744 primarily targets old web browsers that are susceptible to reflected cross-site scripting.