THREAT OPS › Threat News › [NVD] CVE-2024-3822 (MEDIUM 4.8) — The Base64 Encoder/Decoder WordPress plugin through 0.9.2 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin
[NVD] CVE-2024-3822 (MEDIUM 4.8) — The Base64 Encoder/Decoder WordPress plugin through 0.9.2 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin
CVE-2024-3822 CVSS: 4.8 MEDIUM Published: 2024-05-15T06:15:14.377
The Base64 Encoder/Decoder WordPress plugin through 0.9.2 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin
Indicators of compromise
- CVE-2024-3822cve
Original source: https://nvd.nist.gov/vuln/detail/CVE-2024-3822