CVE-2024-7655

Published
View on NVD ↗
CVSS v3
4.4
MEDIUM
CVSS v2
N/A
Affected
1
PROJECT

Description

The Community by PeepSo – Social Network, Membership, Registration, User Profiles plugin for WordPress is vulnerable to Stored Cross-Site Scripting in all versions up to, and including, 6.4.5.0 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level access, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. This only affects multi-site installations and installations where unfiltered_html has been disabled.

<p>We decided to stop using WordPress.org Plugins Repository. To get PeepSo plugins, please go to: <a href="https://peepso.com/pricing" rel="nofollow ugc">PeepSo.com</a> &#8211; you can download free PeepSo plugin there.</p> <h3>More Information</h3> <p>More plugins are currently being developed to extend PeepSo&#8217;s functionality. To get your desired plugin, see our <a href="https://www.peepso.com/pricing/" rel="nofollow ugc">PeepSo Pricing Page</a>.</p>
WordPress Plugin DirectoryWordPress Plugin Directory
469K