The Starbox WordPress plugin before 3.5.3 does not properly render social media profiles URLs in certain contexts, like the malicious user's profile or pages where the starbox shortcode is used, which may be abused by users with at least the contributor role to conduct Stored XSS attacks.
Metrics
Affected Vendors & Products
References
History
Mon, 07 Oct 2024 16:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Squirrly
Squirrly starbox |
|
| Weaknesses | CWE-79 | |
| CPEs | cpe:2.3:a:squirrly:starbox:*:*:*:*:*:wordpress:*:* | |
| Vendors & Products |
Squirrly
Squirrly starbox |
Tue, 01 Oct 2024 14:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Squirrlyuk
Squirrlyuk starbox |
|
| CPEs | cpe:2.3:a:squirrlyuk:starbox:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Squirrlyuk
Squirrlyuk starbox |
|
| Metrics |
cvssV3_1
|
Mon, 30 Sep 2024 06:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | The Starbox WordPress plugin before 3.5.3 does not properly render social media profiles URLs in certain contexts, like the malicious user's profile or pages where the starbox shortcode is used, which may be abused by users with at least the contributor role to conduct Stored XSS attacks. | |
| Title | Starbox < 3.5.3 - Contributor+ Stored XSS | |
| References |
|
Status: PUBLISHED
Assigner: WPScan
Published:
Updated: 2024-10-01T13:58:54.159Z
Reserved: 2024-08-27T18:59:09.028Z
Link: CVE-2024-8239
Updated: 2024-10-01T13:58:40.692Z
Status : Analyzed
Published: 2024-09-30T06:15:14.520
Modified: 2024-10-07T15:48:35.887
Link: CVE-2024-8239
No data.