NA

CVE-2024-3867

Published: 16/04/2024 Updated: 16/04/2024

Vulnerability Summary

The archive-tainacan-collection theme for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of add_query_arg without appropriate escaping on the URL in version 2.7.2. This makes it possible for unauthenticated malicious users to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a link.

Github Repositories

Exploiting Reflected Cross-Site Scripting (XSS) in WordPress archive-tainacan-collection Theme

😈 Exploiting Reflected Cross-Site Scripting (XSS) in WordPress archive-tainacan-collection Theme 😈 Description: This exploit leverages a vulnerability found in version 271 of the WordPress archive-tainacan-collection theme (CVE-2024-3867) By utilizing the unescaped add_query_arg method for URLs, unauthorized attackers can inject arbitrary web scripts By enticing a use