CVE-2024-7655
Published
CVSS v3
4.4
MEDIUM
CVSS v2
N/A
Affected
1
PROJECT
Description
The Community by PeepSo – Social Network, Membership, Registration, User Profiles plugin for WordPress is vulnerable to Stored Cross-Site Scripting in all versions up to, and including, 6.4.5.0 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level access, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. This only affects multi-site installations and installations where unfiltered_html has been disabled.
<p>We decided to stop using WordPress.org Plugins Repository. To get PeepSo plugins, please go to: <a href="https://peepso.com/pricing" rel="nofollow ugc">PeepSo.com</a> – you can download free PeepSo plugin there.</p>
<h3>More Information</h3>
<p>More plugins are currently being developed to extend PeepSo’s functionality. To get your desired plugin, see our <a href="https://www.peepso.com/pricing/" rel="nofollow ugc">PeepSo Pricing Page</a>.</p>