The Starbox WordPress plugin before 3.5.3 does not properly render social media profiles URLs in certain contexts, like the malicious user's profile or pages where the starbox shortcode is used, which may be abused by users with at least the contributor role to conduct Stored XSS attacks.
Metrics
Affected Vendors & Products
References
History
Mon, 07 Oct 2024 16:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
First Time appeared |
Squirrly
Squirrly starbox |
|
Weaknesses | CWE-79 | |
CPEs | cpe:2.3:a:squirrly:starbox:*:*:*:*:*:wordpress:*:* | |
Vendors & Products |
Squirrly
Squirrly starbox |
Tue, 01 Oct 2024 14:30:00 +0000
Type | Values Removed | Values Added |
---|---|---|
First Time appeared |
Squirrlyuk
Squirrlyuk starbox |
|
CPEs | cpe:2.3:a:squirrlyuk:starbox:*:*:*:*:*:*:*:* | |
Vendors & Products |
Squirrlyuk
Squirrlyuk starbox |
|
Metrics |
cvssV3_1
|
Mon, 30 Sep 2024 06:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | The Starbox WordPress plugin before 3.5.3 does not properly render social media profiles URLs in certain contexts, like the malicious user's profile or pages where the starbox shortcode is used, which may be abused by users with at least the contributor role to conduct Stored XSS attacks. | |
Title | Starbox < 3.5.3 - Contributor+ Stored XSS | |
References |
|

Status: PUBLISHED
Assigner: WPScan
Published:
Updated: 2024-10-01T13:58:54.159Z
Reserved: 2024-08-27T18:59:09.028Z
Link: CVE-2024-8239

Updated: 2024-10-01T13:58:40.692Z

Status : Analyzed
Published: 2024-09-30T06:15:14.520
Modified: 2024-10-07T15:48:35.887
Link: CVE-2024-8239

No data.