CVE-2024-8187: Smart Post Show <= 3.0.0 - Editor+ Stored XSS
The Smart Post Show WordPress plugin before 3.0.1 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfilteredhtml capability is disallowed (for example in multisite setup).
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-8187?
CVE-2024-8187 is classified as a high severity vulnerability due to its potential for Stored Cross-Site Scripting attacks.
How do I fix CVE-2024-8187?
To fix CVE-2024-8187, update the Smart Post Show WordPress plugin to version 3.0.1 or later.
Who is affected by CVE-2024-8187?
CVE-2024-8187 affects users of the Smart Post Show WordPress plugin versions prior to 3.0.1.
What type of attack is possible with CVE-2024-8187?
CVE-2024-8187 allows high privilege users to conduct Stored Cross-Site Scripting attacks.
Can CVE-2024-8187 affect multisite WordPress installations?
Yes, CVE-2024-8187 can affect multisite WordPress installations where unfiltered_html capability is disallowed.