CVE-2024-8857: WordPress Auction <= 3.7 - Editor+ Stored XSS
The WordPress Auction Plugin WordPress plugin through 3.7 does not sanitise and escape some of its settings, which could allow high privilege users such as editors to perform Stored Cross-Site Scripting attacks.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-8857?
CVE-2024-8857 is considered a high severity vulnerability due to its potential for Stored Cross-Site Scripting attacks.
How do I fix CVE-2024-8857?
To fix CVE-2024-8857, update the WordPress Auction Plugin to version 3.8 or higher where the vulnerability has been addressed.
Who is affected by CVE-2024-8857?
Users of the WordPress Auction Plugin version 3.7 and below are affected by CVE-2024-8857.
What is the impact of CVE-2024-8857?
The impact of CVE-2024-8857 includes potential Stored Cross-Site Scripting attacks carried out by high privilege users.
What versions are vulnerable to CVE-2024-8857?
All versions of the WordPress Auction Plugin up to and including version 3.7 are vulnerable to CVE-2024-8857.