First published: Fri Sep 06 2024(Updated: )
The Advanced Sermons plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘sermon_video_embed’ parameter in all versions up to, and including, 3.3 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
Credit: security@wordfence.com
Affected Software | Affected Version | How to fix |
---|---|---|
WordPress Advanced Sermons | <3.4 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2024-7599 has a severity rating that can impact user security due to stored cross-site scripting vulnerabilities.
To resolve CVE-2024-7599, update the Advanced Sermons plugin to version 3.4 or later, which includes necessary security fixes.
CVE-2024-7599 affects all versions of the Advanced Sermons plugin for WordPress up to 3.3.
CVE-2024-7599 is a stored cross-site scripting vulnerability due to insufficient input sanitization and output escaping.
Yes, authenticated attackers can exploit CVE-2024-7599 by injecting malicious scripts through the 'sermon_video_embed' parameter.