NA

CVE-2024-2848

Published: 29/03/2024 Updated: 29/03/2024

Vulnerability Summary

The Responsive theme for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the save_footer_text_callback function in all versions up to, and including, 5.0.2. This makes it possible for unauthenticated malicious users to inject arbitrary HTML content into the site's footer.

Mailing Lists

<!--X-Body-Begin--> <!--X-User-Header--> oss-sec mailing list archives <!--X-User-Header-End--> <!--X-TopPNI--> By Date By Thread </form> <!--X-TopPNI-End--> <!--X-MsgBody--> <!--X-Subject-Header-Begin--> Wordpress Responsive theme: arbitrary HTML content injection (CVE-2024-2848) <!--X-Subject-Header-End--> <!--X-Head-of-Message ...