Vulnerability Description
The MM-email2image WordPress plugin through 0.2.5 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Mmilan81 | Mm-Email2Image | <= 0.2.5 |
Related Weaknesses (CWE)
References
- https://wpscan.com/vulnerability/450375f6-a9d4-49f6-8bab-867774372795/ExploitThird Party Advisory
- https://wpscan.com/vulnerability/450375f6-a9d4-49f6-8bab-867774372795/ExploitThird Party Advisory
FAQ
What is CVE-2024-3075?
CVE-2024-3075 is a vulnerability with a CVSS score of 8.1 (HIGH). The MM-email2image WordPress plugin through 0.2.5 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could all...
How severe is CVE-2024-3075?
CVE-2024-3075 has been rated HIGH with a CVSS base score of 8.1/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2024-3075?
Check the references section above for vendor advisories and patch information. Affected products include: Mmilan81 Mm-Email2Image.