CVE · Medium

CVE-2024-52268 — VK All in One Expansion Unit [vk-all-in-one-expansion-unit] < 9.100.1.0

CVE Vulnerability Type Severity Affected Fixed in Published Status
CVE-2024-52268 VK All in One Expansion Unit [vk-all-in-one-expansion-unit] < 9.100.1.0 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Medium 4.8 < 9.100.1.0 9.100.1.0 2024-11-13

CVE-2024-52268

The VK All in One Expansion Unit WordPress plugin before version 9.100.1.0 contains a stored cross-site scripting flaw in its Custom Alert Content feature that allows attackers to inject malicious scripts. This vulnerability, identified as CWE-79, was discovered by Umeda Yuugo at Tokyo Denki University and coordinated through JPCERT/CC's partnership with the developer.

Based on public CVE data (MITRE/NVD).

Scan your WordPress site free

No signup, no credit card — enter your URL and get a security report in seconds.