CVE-2024-55864
Published
CVSS v3
N/A
CVSS v2
N/A
Affected
1
PROJECT
Description
Cross-site scripting vulnerability exists in My WP Customize Admin/Frontend versions prior to ver 1.24.1. If a malicious administrative user customizes the administrative page with some malicious contents, an arbitrary script may be executed on the web browser of the other users who are accessing the page.
<p><a href="https://mywpcustomize.com" rel="nofollow ugc">My WP Customize</a> is customize for WordPress.</p>
<p>Simply and easy-to-use the customize for Admin and Frontend. A lot of custom filters and actions, and included the developer tools.</p>
<p>There are lots of custom actions and filters.</p>
<p>You will speed up to your site creation. Debug on current post, Debug on current using theme, Debug on server info, …etc more helpful info.</p>
<p>The demo site is here: <a href="https://playground.wordpress.net/?plugin=my-wp&url=/wp-admin/admin.php?page=mywp" rel="nofollow ugc">https://playground.wordpress.net/?plugin=my-wp&url=/wp-admin/admin.php?page=mywp</a></p>
<h4>Customize the admin</h4>
<ul>
<li>Admin General(hide update notifications, hide screen options, custom footer text).</li>
<li>Admin Dashboard(hide meta boxes, change meta box title, restrict meta box order).</li>
<li>Admin Sidebar(hide menus, order menus, change icon and title, add custom link menu).</li>
<li>Admin Toolbar(hide menus, order menus, change icon and title, add custom link menu).</li>
<li>Admin Post list(hide columns, order columns, change title).</li>
<li>Admin Post edit(support block editor and classic editor, hide meta boxes, change title placeholder, restrict order meta box).</li>
<li>Admin Terms(hide columns, order columns, change title).</li>
<li>Admin Media uploads(hide columns, order columns, change title).</li>
<li>Admin Comments(hide columns, order columns, change title).</li>
<li>Admin Users(hide columns, order columns, change title).</li>
<li>Admin User edit(hide Visual Editor checkbox, hide Syntax Highlighting checkbox, hide Admin Color Scheme).</li>
<li>Admin Site editor(Change top left button).</li>
<li>Admin Nav menus(hide meta boxes, hide Link target, hide Title Attribute, hide CSS classes).</li>
</ul>
<h4>Customize the frontend</h4>
<ul>
<li>Frontend General(show and hide toolbar, hide Rest link, hide Shortlink, set X-Frame-Options, add custom header meta).</li>
<li>Frontend Author archive(hide archive page, add Disallow to robots.txt).</li>
<li>Frontend Date archive(hide archive page).</li>
<li>Frontend Taxonomy archive(hide archive page).</li>
<li>Frontend Toolbar(hide menus, order menus, change icon and title, add custom link menu).</li>
</ul>
<h4>Customize the login</h4>
<ul>
<li>Login General(Change logo link and image, hide select language, add custom footer text).</li>
<li>Login User(redirect after login and logout).</li>
</ul>
<h4>Customize the website</h4>
<ul>
<li>Site General(Disable file edit, hide PHP X-Mailer version).</li>
<li>Site Post type(Change create_posts capability).</li>
<li>Site Sitemap(hide core sitemap.xml).</li>
</ul>
<h4>For Debug</h4>
<ul>
<li>Debug General(Display a debug screen that is useful for development).</li>
<li>Debug Blogs(Show all blogs on network/multisite).</li>
<li>Debug Crons(Show all crons).</li>
<li>Debug Date time(Show all date and time values).</li>
<li>Debug Defines(Show all defines).</li>
<li>Debug Post statuses(Show all post statuses).</li>
<li>Debug Post structure(Show a post structure).</li>
<li>Debug Post types(Show all post types).</li>
<li>Debug Rest API(Show all rest api).</li>
<li>Debug Site options(Show all site options on network/multisite).</li>
<li>Debug Taxonomies(Show all taxonomies).</li>
<li>Debug Terms(Show all terms).</li>
<li>Debug transients(Show all transients).</li>
<li>Debug translations(Show all translations).</li>
<li>Debug Capabilities(Show all user roles capabilities).</li>
</ul>