CVE · Medium

CVE-2024-4473 — Sydney Toolbox [sydney-toolbox] < 1.32

CVE Vulnerability Type Severity Affected Fixed in Published Status
CVE-2024-4473 Sydney Toolbox [sydney-toolbox] < 1.32 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Medium 5.4 < 1.32 1.32 2024-05-13

CVE-2024-4473

The Sydney Toolbox plugin contains a stored cross-site scripting vulnerability in the aThemes Portfolio widget affecting versions 1.31 and below, caused by inadequate sanitization of user input and escaping of output in widget attributes. Attackers with contributor-level permissions or higher can inject malicious scripts into pages that will execute when other users view the affected content. This vulnerability impacts all versions up to and including 1.31, with fixes expected in version 1.32 and later.

Based on public CVE data (MITRE/NVD).

Scan your WordPress site free

No signup, no credit card — enter your URL and get a security report in seconds.