CVE-2024-3963

Severity
6.5MEDIUM
EPSS
0.2%
top 52.69%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedJul 13

Description

The Giveaways and Contests by RafflePress WordPress plugin before 1.12.14 does not sanitise and escape some parameters, which could allow users with a role as low as editor to perform Cross-Site Scripting attacks

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:LExploitability: 2.3 | Impact: 3.7

Affected Packages2 packages

🔴Vulnerability Details

2
CVEList
RafflePress Lite < 1.12.14 - Editor+ Stored XSS2024-07-13
GHSA
GHSA-cf3c-mjjg-mw7c: The Giveaways and Contests by RafflePress WordPress plugin before 12024-07-13
CVE-2024-3963 (MEDIUM CVSS 6.5) | The Giveaways and Contests by Raffl | cvebase.io