Unrated severityNVD Advisory· Published Jun 13, 2024· Updated Aug 2, 2024
WordPress Cooked Plugin - Authenticated (Contributor+) Persistent Cross-Site Scripting Vulnerability
CVE-2024-37308
Description
The Cooked Pro recipe plugin for WordPress is vulnerable to Persistent Cross-Site Scripting (XSS) via the _recipe_settings[post_title] parameter in versions up to, and including, 1.7.15.4 due to insufficient input sanitization and output escaping. This vulnerability allows authenticated attackers with contributor-level access and above to inject arbitrary web scripts in pages that will execute whenever a user accesses a compromised page. A patch is available at commit 8cf88f334ccbf11134080bbb655c66f1cfe77026 and will be part of version 1.8.0.
Affected products
1Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
2- github.com/XjSv/Cooked/commit/8cf88f334ccbf11134080bbb655c66f1cfe77026mitrex_refsource_MISC
- github.com/XjSv/Cooked/security/advisories/GHSA-9vfv-c966-jwrvmitrex_refsource_CONFIRM
News mentions
0No linked articles in our index yet.