CVE-2024-9938: Bounce Handler MailPoet 3 <= 1.3.21 - Reflected Cross-Site Scripting
The Bounce Handler MailPoet 3 plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'page' parameter in all versions up to, and including, 1.3.21 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a link.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-9938?
CVE-2024-9938 is rated as a medium severity vulnerability, posing a risk of reflected cross-site scripting.
How do I fix CVE-2024-9938?
To fix CVE-2024-9938, update the MailPoet 3 plugin to version 1.3.22 or later, which includes patches for this vulnerability.
Who is affected by CVE-2024-9938?
CVE-2024-9938 affects all versions of the MailPoet 3 plugin for WordPress up to and including version 1.3.21.
What kind of attacks can CVE-2024-9938 enable?
CVE-2024-9938 enables unauthenticated attackers to perform reflected cross-site scripting attacks.
Is authentication required to exploit CVE-2024-9938?
No, CVE-2024-9938 can be exploited by unauthenticated attackers, making it critical to address.