PoC Index

CVE-2024-4477

MEDIUM 5.4EPSS 0.3%

The WP Logs Book WordPress plugin through 1.0.1 does not sanitise and escape some of its log data before outputting them back in an admin dashboard, leading to an Unauthenticated Stored Cross-Site Scripting

CVSS v3.1
5.4 MEDIUMCVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
CVSS v3.1
4.3 MEDIUMCVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:U/C:L/I:L/A:L
EPSS
0.31% chance of exploitation in the next 30 days, 23th percentile
Published
2024-06-21
Updated
2024-08-01

Proof-of-concept exploits (1)

References

Related