CVE-2024-9292: Bridge Core <= 3.2.0 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode
The Bridge Core plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'formforall' shortcode in versions up to, and including, 3.2.0 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers with contributor-level and above permissions to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-9292?
CVE-2024-9292 has a medium severity rating due to its potential for exploitation via stored cross-site scripting.
How do I fix CVE-2024-9292?
To fix CVE-2024-9292, update the Bridge Core plugin to version 3.2.1 or later, where the vulnerability has been addressed.
Who is affected by CVE-2024-9292?
CVE-2024-9292 affects users of the Bridge Core plugin for WordPress versions up to and including 3.2.0.
What is the impact of CVE-2024-9292?
The impact of CVE-2024-9292 includes potential data theft, unauthorized actions, and the ability for attackers to execute scripts in the context of an authenticated user.
How can I determine if I'm using the vulnerable version related to CVE-2024-9292?
You can determine if you are using a vulnerable version of the Bridge Core plugin by checking your plugin version in the WordPress admin area.