CVE-2024-4756

June 7, 2024, 2:56 p.m.

Product(s) Impacted

WP Backpack WordPress plugin

  • 2.1

Description

The WP Backpack WordPress plugin through 2.1 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)

Weaknesses

Date

Published: June 7, 2024, 6:15 a.m.

Last Modified: June 7, 2024, 2:56 p.m.

Status : Awaiting Analysis

CVE has been marked for Analysis. Normally once in this state the CVE will be analyzed by NVD staff within 24 hours.

More info

Source

contact@wpscan.com

References