CVE-2024-6897
Published
CVSS v3
6.4
MEDIUM
CVSS v2
N/A
Affected
1
PROJECT
Description
The aThemes Starter Sites plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploads in all versions up to, and including, 1.0.53 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Author-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses the SVG file.
<p>We’ve got a full and ever-growing library stocked with ready-made templates for any kind of business.</p>
<h3>ATHEMES STARTER SITES</h3>
<p>Business owners, freelancers, Online Store Owners, and creatives: get ready to build and launch an awesome website in no-time, all by yourself! With our aThemes Starter Sites plugin, you can take your pick from plenty of starter sites, such as business, portfolio, and e-commerce. Then get creative and customize it to match your branding, all without writing a single line of code. Select the demo that suits your needs, import, tweak, and go live!</p>
<h4>Pick your website template</h4>
<p>We’ve got a full and ever-growing library stocked with ready-made templates for any kind of business.</p>
<h4>Add your own awesome content</h4>
<p>Add your own text, photos, videos, vector art, and more is a breeze by Gutenberg, Elementor, and different website builders.</p>
<h4>Customize your site</h4>
<p>Make your starter site really yours. Tweak your site with different fonts, color palettes, and more to fit your style.</p>
<h4>Let’s go live</h4>
<p>Ready to grow your business with a website that stands out from the crowd? Publish your page in just a few clicks.</p>
<p><strong>Happy Building!</strong></p>
<h4>LIST OF STARTER SITES TO IMPORT</h4>
<ul>
<li><a href="https://athemes.com/sydney-demos/" rel="nofollow ugc">Sydney Starters Sites</a></li>
<li><a href="https://athemes.com/airi-demos/" rel="nofollow ugc">Airi Starters Sites</a></li>
<li><a href="https://athemes.com/theme/botiga/" rel="nofollow ugc">Botiga</a></li>
</ul>