Medium severity6.1NVD Advisory· Published Sep 12, 2024· Updated Jun 17, 2026
CVE-2024-8056
CVE-2024-8056
Description
The MM-Breaking News WordPress plugin through 0.7.9 does not escape the $_SERVER['REQUEST_URI'] parameter before outputting it back in an attribute, which could lead to Reflected Cross-Site Scripting in old web browsers
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
3- cpe:2.3:a:mm-breaking_news_project:mm-breaking_news:*:*:*:*:*:wordpress:*:*Range: <=0.7.9
- Range: <=0.7.9
Patches
Vulnerability mechanics
References
1- wpscan.com/vulnerability/203b8122-f1e5-4e9e-ba83-f5cd59d8a289/nvdExploitThird Party Advisory
News mentions
0No linked articles in our index yet.