CVE-2024-9777: Ashe <= 2.243 - Reflected Cross-Site Scripting via add_query_arg Parameter
The Ashe theme for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of addqueryarg without appropriate escaping on the URL in all versions up to, and including, 2.243. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a link.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2024-9777?
CVE-2024-9777 is considered a medium severity vulnerability that allows for reflected cross-site scripting attacks.
How do I fix CVE-2024-9777?
To fix CVE-2024-9777, update the Ashe theme for WordPress to version 2.244 or later.
Who is affected by CVE-2024-9777?
All users of the Ashe theme for WordPress, versions up to and including 2.243, are affected by CVE-2024-9777.
What type of vulnerability is CVE-2024-9777?
CVE-2024-9777 is classified as a reflected cross-site scripting (XSS) vulnerability.
Can CVE-2024-9777 be exploited by unauthenticated users?
Yes, CVE-2024-9777 can be exploited by unauthenticated attackers to inject arbitrary web scripts.