CVE-2024-49700
Published: 21 January 2025
Description
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in reputeinfosystems ARPrice arprice allows Reflected XSS.This issue affects ARPrice: from n/a through <= 4.1.3.
Security Summary
CVE-2024-49700 is an Improper Neutralization of Input During Web Page Generation vulnerability, classified as Reflected Cross-site Scripting (XSS) under CWE-79, in the ARPrice WordPress plugin developed by reputeinfosystems. The issue affects ARPrice versions from n/a through 4.1.3 inclusive.
With a CVSS v3.1 base score of 7.1 (AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L), the vulnerability is exploitable over the network with low attack complexity and no required privileges, though it demands user interaction. Remote attackers can trick authenticated or unauthenticated users into interacting with maliciously crafted links or inputs reflected in the plugin's web page generation, enabling script injection in the victim's browser context and achieving low impacts on confidentiality, integrity, and availability alongside a scope change.
Patchstack provides details on the vulnerability in its advisory at https://patchstack.com/database/Wordpress/Plugin/arprice/vulnerability/wordpress-arprice-plugin-4-0-3-reflected-cross-site-scripting-xss-vulnerability?_s_id=cve, which security practitioners should consult for recommended mitigations and patch information.
Details
- CWE(s)