CVE-2024-5802: URL Shortener by MyThemeShop <= 1.0.17 - Admin+ Stored XSS
The URL Shortener by Myhop WordPress plugin through 1.0.17 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Cross-Site Scripting attacks even when unfilteredhtml is disallowed
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-5802?
CVE-2024-5802 is classified as a medium severity vulnerability due to the potential for Cross-Site Scripting attacks by high privilege users.
How do I fix CVE-2024-5802?
To fix CVE-2024-5802, update the URL Shortener by Myhop WordPress plugin to version 1.0.18 or later to ensure proper sanitization of settings.
What type of vulnerability is CVE-2024-5802?
CVE-2024-5802 is a Cross-Site Scripting (XSS) vulnerability that affects the URL Shortener by Myhop WordPress plugin.
Who is affected by CVE-2024-5802?
CVE-2024-5802 affects high privilege users, such as administrators, using the vulnerable version of the URL Shortener by Myhop plugin.
Can CVE-2024-5802 be exploited without admin access?
No, CVE-2024-5802 requires high privilege access, such as an admin account, to exploit the vulnerability.