CVE-2024-7084

Severity
4.8MEDIUM
EPSS
0.2%
top 59.63%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedAug 6

Description

The Ajax Search Lite WordPress plugin before 4.12.1 does not sanitise and escape some parameters, which could allow users with a role as low as Admin+ to perform Cross-Site Scripting attacks.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:NExploitability: 1.7 | Impact: 2.7

Affected Packages2 packages

CVEListV5unknown/ajax_search_lite< 4.12.1
NVDwp-dreams/ajax_search< 4.12.1

🔴Vulnerability Details

2
CVEList
Ajax Search Lite < 4.12.1 - Admin+ Stored XSS2024-08-06
GHSA
GHSA-fj5p-6c44-4pp3: The Ajax Search Lite WordPress plugin before 42024-08-06
CVE-2024-7084 (MEDIUM CVSS 4.8) | The Ajax Search Lite WordPress plug | cvebase.io