CVE-2024-8857

CVE-2024-8857: WordPress Auction <= 3.7 - Editor+ Stored XSS

Vendor Unknown
Product WordPress Auction Plugin
Published January 7, 2025
Last update January 7, 2025

CVSS base score

What the vulnerability does

01Description

The WordPress Auction Plugin WordPress plugin through 3.7 does not sanitise and escape some of its settings, which could allow high privilege users such as editors to perform Stored Cross-Site Scripting attacks.

Key dates

02Disclosure timeline

January 7, 2025 CVE published
January 7, 2025 Record updated