CVE-2024-10309

The Tracking Code Manager WordPress plugin before 2.4.0 does not sanitise and escape some of its metabox settings when outputing them in the page, which could allow users with a role as low as Contributor to perform Cross-Site Scripting attacks.
Configurations

Configuration 1 (hide)

cpe:2.3:a:data443:tracking_code_manager:*:*:*:*:*:wordpress:*:*

History

11 May 2025, 23:38

Type Values Removed Values Added
CWE CWE-79
First Time Data443 tracking Code Manager
Data443
Summary
  • (es) El complemento Tracking Code Manager de WordPress anterior a la versión 2.4.0 no desinfecta ni escapa algunas de las configuraciones de su metabox al mostrarlas en la página, lo que podría permitir que los usuarios con un rol tan bajo como Colaborador realicen ataques de Cross-Site Scripting.
CPE cpe:2.3:a:data443:tracking_code_manager:*:*:*:*:*:wordpress:*:*
References () https://wpscan.com/vulnerability/9eb21250-34bd-4600-a0a5-7c5117f69f04/ - () https://wpscan.com/vulnerability/9eb21250-34bd-4600-a0a5-7c5117f69f04/ - Exploit, Third Party Advisory

30 Jan 2025, 17:15

Type Values Removed Values Added
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 5.9
References () https://wpscan.com/vulnerability/9eb21250-34bd-4600-a0a5-7c5117f69f04/ - () https://wpscan.com/vulnerability/9eb21250-34bd-4600-a0a5-7c5117f69f04/ -

30 Jan 2025, 06:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-01-30 06:15

Updated : 2025-05-11 23:38


NVD link : CVE-2024-10309

Mitre link : CVE-2024-10309

CVE.ORG link : CVE-2024-10309


JSON object : View

Products Affected

data443

  • tracking_code_manager
CWE
CWE-79

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')