The Website Article Monetization By MageNet plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'abp_auth_key' parameter in all versions up to, and including, 1.0.11 due to insufficient input sanitization and output escaping and a missing authorization check. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
History

Mon, 24 Mar 2025 15:15:00 +0000

Type Values Removed Values Added
First Time appeared Magenet
Magenet website Article Monetization
Weaknesses CWE-79
CPEs cpe:2.3:a:magenet:website_article_monetization:*:*:*:*:*:wordpress:*:*
Vendors & Products Magenet
Magenet website Article Monetization

cve-icon MITRE

Status: PUBLISHED

Assigner: Wordfence

Published:

Updated: 2024-08-05T16:22:25.309Z

Reserved: 2024-02-08T20:23:15.857Z

Link: CVE-2024-1379

cve-icon Vulnrichment

Updated: 2024-08-01T18:40:20.402Z

cve-icon NVD

Status : Analyzed

Published: 2024-03-20T07:15:09.903

Modified: 2025-03-24T14:48:13.980

Link: CVE-2024-1379

cve-icon Redhat

No data.