CVE-2024-6798: DL Verification <= 1.2 - Admin+ Stored XSS
The DL Verification WordPress plugin through 1.2 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfilteredhtml capability is disallowed (for example in multisite setup).
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-6798?
CVE-2024-6798 is a high severity vulnerability due to the potential for stored Cross-Site Scripting attacks.
Who is affected by CVE-2024-6798?
CVE-2024-6798 affects users of the DL Verification WordPress plugin version 1.2 and earlier.
How can I fix CVE-2024-6798?
To fix CVE-2024-6798, update the DL Verification WordPress plugin to a version later than 1.2.
What type of vulnerability is CVE-2024-6798?
CVE-2024-6798 is a stored Cross-Site Scripting vulnerability, allowing attackers to inject malicious scripts.
What are the implications of CVE-2024-6798 for administrators?
Administrators can be exploited through CVE-2024-6798, as high privilege users can execute malicious scripts that compromise site security.