CVE-2024-10515

In the process of testing the SEO Plugin by Squirrly SEO WordPress plugin before 12.3.21, a vulnerability was found that allows you to implement Stored XSS on behalf of the editor by embedding malicious script, which entails account takeover backdoor
References
Configurations

Configuration 1 (hide)

cpe:2.3:a:squirrly:seo_plugin_by_squirrly_seo:*:*:*:*:*:wordpress:*:*

History

31 Mar 2025, 19:33

Type Values Removed Values Added
CPE cpe:2.3:a:squirrly:seo_plugin_by_squirrly_seo:*:*:*:*:*:wordpress:*:*
CWE CWE-79
References () https://wpscan.com/vulnerability/367aad17-fbb5-48eb-8829-5d3513098d02/ - () https://wpscan.com/vulnerability/367aad17-fbb5-48eb-8829-5d3513098d02/ - Exploit, Third Party Advisory
First Time Squirrly
Squirrly seo Plugin By Squirrly Seo

21 Nov 2024, 13:57

Type Values Removed Values Added
Summary
  • (es) En el proceso de prueba del complemento SEO de WordPress de Squirrly SEO Plugin anterior a la versión 12.3.21, se encontró una vulnerabilidad que permite implementar XSS almacenado en nombre del editor mediante la incorporación de un script malicioso, lo que implica una puerta trasera de apropiación de cuentas.

20 Nov 2024, 16:35

Type Values Removed Values Added
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 3.5

20 Nov 2024, 06:15

Type Values Removed Values Added
New CVE

Information

Published : 2024-11-20 06:15

Updated : 2025-03-31 19:33


NVD link : CVE-2024-10515

Mitre link : CVE-2024-10515

CVE.ORG link : CVE-2024-10515


JSON object : View

Products Affected

squirrly

  • seo_plugin_by_squirrly_seo
CWE
CWE-79

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')