CVE-2024-5079

July 13, 2024, 6:15 a.m.

Product(s) Impacted

wp-eMember WordPress plugin

  • before 10.6.7

Description

The wp-eMember WordPress plugin before 10.6.7 does not sanitise and escape some of the fields when members register, which allows unauthenticated users to perform Stored Cross-Site Scripting attacks

Weaknesses

Date

Published: July 13, 2024, 6:15 a.m.

Last Modified: July 13, 2024, 6:15 a.m.

Status : Received

CVE has been recently published to the CVE List and has been received by the NVD.

More info

Source

contact@wpscan.com

References