The Sydney Toolbox plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the "aThemes: Portfolio" widget in all versions up to, and including, 1.31 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
History

Thu, 20 Feb 2025 21:15:00 +0000

Type Values Removed Values Added
First Time appeared Athemes
Athemes sydney Toolbox
Weaknesses CWE-79
CPEs cpe:2.3:a:athemes:sydney_toolbox:*:*:*:*:*:wordpress:*:*
Vendors & Products Athemes
Athemes sydney Toolbox

cve-icon MITRE

Status: PUBLISHED

Assigner: Wordfence

Published:

Updated: 2024-08-01T20:40:47.247Z

Reserved: 2024-05-03T19:02:37.887Z

Link: CVE-2024-4473

cve-icon Vulnrichment

Updated: 2024-08-01T20:40:47.247Z

cve-icon NVD

Status : Analyzed

Published: 2024-05-14T16:17:35.160

Modified: 2025-02-20T20:59:09.933

Link: CVE-2024-4473

cve-icon Redhat

No data.