CVE-2024-8239: Starbox < 3.5.3 - Contributor+ Stored XSS
The Starbox WordPress plugin before 3.5.3 does not properly render social media profiles URLs in certain contexts, like the malicious user's profile or pages where the starbox shortcode is used, which may be abused by users with at least the contributor role to conduct Stored XSS attacks.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-8239?
CVE-2024-8239 has a critical severity level due to its potential for Stored XSS vulnerabilities.
How do I fix CVE-2024-8239?
To fix CVE-2024-8239, upgrade the Squirrly Starbox WordPress plugin to version 3.5.3 or later.
Who is affected by CVE-2024-8239?
Users with at least the contributor role in WordPress are affected by CVE-2024-8239.
What type of attack does CVE-2024-8239 facilitate?
CVE-2024-8239 facilitates Stored XSS attacks through improperly rendered social media profile URLs.
What software version is vulnerable to CVE-2024-8239?
Versions of the Squirrly Starbox plugin prior to 3.5.3 are vulnerable to CVE-2024-8239.