CVE-2024-8317: WP AdCenter – Ad Manager & Adsense Ads <= 2.5.6 - Authenticated (Contributor+) Stored Cross-Site Scripting via ad_alignment Attribute
The WP AdCenter – Ad Manager & Adsense Ads plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘adalignment’ attribute in all versions up to, and including, 2.5.6 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
Affected Software
Remediation
Patch Available
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2024-8317?
CVE-2024-8317 is classified as a medium severity vulnerability due to its potential for stored cross-site scripting attacks.
How do I fix CVE-2024-8317?
To fix CVE-2024-8317, update the WP AdCenter plugin to version 2.5.7 or later to ensure proper input sanitization and output escaping.
What versions are affected by CVE-2024-8317?
CVE-2024-8317 affects all versions of the WP AdCenter plugin up to and including version 2.5.6.
What is the impact of CVE-2024-8317?
The impact of CVE-2024-8317 could allow authenticated users to inject malicious scripts that can affect other users of the site.
Who is impacted by CVE-2024-8317?
Users of the WP AdCenter plugin for WordPress who are running versions 2.5.6 or earlier are impacted by CVE-2024-8317.