CVE-2024-8492: Hustle < 7.8.5 - Admin+ Stored XSS
The Hustle WordPress plugin through 7.8.5 does not sanitise and escape some of its settings, which could allow high privilege users such as editors to perform Cross-Site Scripting attacks even when unfilteredhtml is disallowed
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-8492?
CVE-2024-8492 is classified as a high-severity vulnerability due to its potential for Cross-Site Scripting attacks by high-privilege users.
How do I fix CVE-2024-8492?
To fix CVE-2024-8492, update the Hustle WordPress plugin to version 7.8.6 or later, which includes the necessary patches.
Who is affected by CVE-2024-8492?
CVE-2024-8492 affects users of the Hustle WordPress plugin versions up to 7.8.5, particularly high-privilege users such as editors.
What type of vulnerability is CVE-2024-8492?
CVE-2024-8492 is a Cross-Site Scripting (XSS) vulnerability due to improper sanitization and escaping of user settings.
Can CVE-2024-8492 be exploited without elevated privileges?
No, CVE-2024-8492 requires elevated privileges, as it can only be exploited by high-privilege users like editors.