CVE-2024-6339: Phlox PRO <= 5.16.4 - Reflected Cross-Site Scripting via Search Parameters
The Phlox PRO theme for WordPress is vulnerable to Reflected Cross-Site Scripting via search parameters in all versions up to, and including, 5.16.4 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a link.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-6339?
CVE-2024-6339 is considered a medium severity vulnerability due to its potential for exploitation via reflected cross-site scripting.
How do I fix CVE-2024-6339?
To fix CVE-2024-6339, update the Phlox PRO theme for WordPress to version 5.16.5 or later.
Who is affected by CVE-2024-6339?
CVE-2024-6339 affects all versions of the Phlox PRO theme for WordPress up to and including 5.16.4.
What type of vulnerability is CVE-2024-6339?
CVE-2024-6339 is a Reflected Cross-Site Scripting vulnerability that arises from insufficient input sanitization.
Can unauthenticated attackers exploit CVE-2024-6339?
Yes, unauthenticated attackers can exploit CVE-2024-6339 to inject arbitrary web scripts via the search parameters.