CVE-2024-5802

July 9, 2024, 6:19 p.m.

Awaiting Analysis
CVE has been recently published to the CVE List and has been received by the NVD.

Products

URL Shortener by Myhop WordPress plugin

  • 1.0.0 - 1.0.17

Source

contact@wpscan.com

Tags

CVE-2024-5802 details

Published : July 9, 2024, 6:15 a.m.
Last Modified : July 9, 2024, 6:19 p.m.

Description

The URL Shortener by Myhop WordPress plugin through 1.0.17 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Cross-Site Scripting attacks even when unfiltered_html is disallowed

CVSS Score

1 2 3 4 5 6 7 8 9 10

Weakness

Weakness Name Description
This website uses the NVD API, but is not approved or certified by it.