5.4
CVSSv3

CVE-2024-2404

Published: 24/04/2024 Updated: 17/05/2024
CVSS v3 Base Score: 5.4 | Impact Score: 2.7 | Exploitability Score: 2.3

Vulnerability Summary

The Better Comments WordPress plugin prior to 1.5.6 does not sanitise and escape some of its settings, which could allow low privilege users such as Subscribers to perform Stored Cross-Site Scripting attacks.

Vulnerable Product Search on Vulmon Subscribe to Product

utopique better comments