CVE-2024-55864

Published
View on NVD ↗
CVSS v3
N/A
CVSS v2
N/A
Affected
1
PROJECT

Description

Cross-site scripting vulnerability exists in My WP Customize Admin/Frontend versions prior to ver 1.24.1. If a malicious administrative user customizes the administrative page with some malicious contents, an arbitrary script may be executed on the web browser of the other users who are accessing the page.

<p><a href="https://mywpcustomize.com" rel="nofollow ugc">My WP Customize</a> is customize for WordPress.</p> <p>Simply and easy-to-use the customize for Admin and Frontend. A lot of custom filters and actions, and included the developer tools.</p> <p>There are lots of custom actions and filters.</p> <p>You will speed up to your site creation. Debug on current post, Debug on current using theme, Debug on server info, &#8230;etc more helpful info.</p> <p>The demo site is here: <a href="https://playground.wordpress.net/?plugin=my-wp&amp;url=/wp-admin/admin.php?page=mywp" rel="nofollow ugc">https://playground.wordpress.net/?plugin=my-wp&amp;url=/wp-admin/admin.php?page=mywp</a></p> <h4>Customize the admin</h4> <ul> <li>Admin General(hide update notifications, hide screen options, custom footer text).</li> <li>Admin Dashboard(hide meta boxes, change meta box title, restrict meta box order).</li> <li>Admin Sidebar(hide menus, order menus, change icon and title, add custom link menu).</li> <li>Admin Toolbar(hide menus, order menus, change icon and title, add custom link menu).</li> <li>Admin Post list(hide columns, order columns, change title).</li> <li>Admin Post edit(support block editor and classic editor, hide meta boxes, change title placeholder, restrict order meta box).</li> <li>Admin Terms(hide columns, order columns, change title).</li> <li>Admin Media uploads(hide columns, order columns, change title).</li> <li>Admin Comments(hide columns, order columns, change title).</li> <li>Admin Users(hide columns, order columns, change title).</li> <li>Admin User edit(hide Visual Editor checkbox, hide Syntax Highlighting checkbox, hide Admin Color Scheme).</li> <li>Admin Site editor(Change top left button).</li> <li>Admin Nav menus(hide meta boxes, hide Link target, hide Title Attribute, hide CSS classes).</li> </ul> <h4>Customize the frontend</h4> <ul> <li>Frontend General(show and hide toolbar, hide Rest link, hide Shortlink, set X-Frame-Options, add custom header meta).</li> <li>Frontend Author archive(hide archive page, add Disallow to robots.txt).</li> <li>Frontend Date archive(hide archive page).</li> <li>Frontend Taxonomy archive(hide archive page).</li> <li>Frontend Toolbar(hide menus, order menus, change icon and title, add custom link menu).</li> </ul> <h4>Customize the login</h4> <ul> <li>Login General(Change logo link and image, hide select language, add custom footer text).</li> <li>Login User(redirect after login and logout).</li> </ul> <h4>Customize the website</h4> <ul> <li>Site General(Disable file edit, hide PHP X-Mailer version).</li> <li>Site Post type(Change create_posts capability).</li> <li>Site Sitemap(hide core sitemap.xml).</li> </ul> <h4>For Debug</h4> <ul> <li>Debug General(Display a debug screen that is useful for development).</li> <li>Debug Blogs(Show all blogs on network/multisite).</li> <li>Debug Crons(Show all crons).</li> <li>Debug Date time(Show all date and time values).</li> <li>Debug Defines(Show all defines).</li> <li>Debug Post statuses(Show all post statuses).</li> <li>Debug Post structure(Show a post structure).</li> <li>Debug Post types(Show all post types).</li> <li>Debug Rest API(Show all rest api).</li> <li>Debug Site options(Show all site options on network/multisite).</li> <li>Debug Taxonomies(Show all taxonomies).</li> <li>Debug Terms(Show all terms).</li> <li>Debug transients(Show all transients).</li> <li>Debug translations(Show all translations).</li> <li>Debug Capabilities(Show all user roles capabilities).</li> </ul>
WordPress Plugin DirectoryWordPress Plugin Directory
121K