CVE · Medium

CVE-2024-5645 — Envo Extra [envo-extra] < 1.8.25

CVE Vulnerability Type Severity Affected Fixed in Published Status
CVE-2024-5645 Envo Extra [envo-extra] < 1.8.25 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Medium 5.4 < 1.8.25 1.8.25 2024-06-06

CVE-2024-5645

A vulnerability exists in the Envo Extra plugin for WordPress, specifically in versions up to 1.8.23, where an attacker with Contributor-level access or higher can inject malicious web scripts into pages through the 'button_css_id' parameter in the Button widget. This occurs due to inadequate input validation and output protection, allowing the attacker to inject arbitrary web scripts that will execute when accessed by other users. As a result, an attacker can potentially inject malicious code into pages, which can then be executed by unsuspecting users.

Based on public CVE data (MITRE/NVD).

Scan your WordPress site free

No signup, no credit card — enter your URL and get a security report in seconds.