CVE-2024-8670 – Photo Gallery by 10Web – Stored XSS to Backdoor Creation – POC

CVE-2024-8670 – Photo Gallery by 10Web – Stored XSS to Backdoor Creation – POC

CVE-2024-8670 reveals a critical Stored Cross-Site Scripting (XSS) vulnerability in the Photo Gallery by 10Web plugin, a popular WordPress plugin with over 200,000 installations. This vulnerability allows contributors or editors to inject malicious JavaScript (JS) into the gallery settings, specifically in the “Title” field. Exploiting this vulnerability can lead to admin account hijacking, persistent backdoor creation, and potential long-term control of the WordPress site.

CVE-2024-10104 – Jobs for WordPress – Stored XSS to Backdoor Creation – POC

CVE-2024-10104 – Jobs for WordPress – Stored XSS to Backdoor Creation – POC

CVE-2024-10104 is a critical Stored Cross-Site Scripting (XSS) vulnerability affecting the Jobs for WordPress plugin, widely used to manage and display job postings on WordPress sites. This vulnerability allows users with Contributor or higher permissions to inject malicious JavaScript (JS) code into the job posting settings, specifically in the “Working Hours” field. Once exploited, the vulnerability can lead to admin account takeovers, unauthorized backdoor installations, and long-term control over the WordPress site.

CVE-2024-8542 – Everest Forms – Stored XSS to Backdoor Creation – POC

CVE-2024-8542 – Everest Forms – Stored XSS to Backdoor Creation – POC

CVE-2024-8542 is a critical Stored Cross-Site Scripting (XSS) vulnerability affecting the Everest Forms plugin, used by over 100,000 WordPress installations to create forms. This flaw allows contributors or editors to inject malicious JavaScript (JS) into the form’s settings, specifically in the “No field” section of the YES/NO block. Once exploited, the vulnerability can lead to admin account takeovers, the creation of backdoors, and long-term control of the WordPress site.

CVE-2024-8284 – Download Manager – Stored XSS to Backdoor Creation – POC

CVE-2024-8284 – Download Manager – Stored XSS to Backdoor Creation – POC

CVE-2024-8284 represents a critical Stored Cross-Site Scripting (XSS) vulnerability discovered in the Download Manager plugin, which is used by over 100,000 WordPress installations to manage and protect downloadable files. This flaw allows attackers with editor-level permissions to inject malicious JavaScript (JS) into the plugin’s settings, specifically in the “Login Required Message” field. Exploiting this vulnerability can result in the creation of backdoors, admin account takeover, and long-term control of the WordPress site.

CVE-2024-5968 – Photo Gallery by 10Web – Stored XSS to Backdoor Creation – POC

CVE-2024-5968 – Photo Gallery by 10Web – Stored XSS to Backdoor Creation – POC

CVE-2024-5968 is a critical vulnerability affecting the Photo Gallery by 10Web plugin, which has over 200,000 active installations. The flaw enables attackers to execute Stored Cross-Site Scripting (XSS) by injecting malicious JavaScript (JS) code into the plugin’s settings. When exploited, this vulnerability allows for admin account takeover, backdoor creation, and potentially long-term control over the WordPress site.

CVE-2024-5429 – Logo Slider Free – Stored XSS to Admin Account Creation – POC

CVE-2024-5429 – Logo Slider Free – Stored XSS to Admin Account Creation – POC

CVE-2024-5429 is a critical vulnerability identified in the Logo Slider Free plugin, which is used by over 30,000 WordPress installations to create logo sliders. The flaw allows an attacker with contributor-level access to inject malicious JavaScript (JS) into the plugin’s settings, specifically in the “Brand Name” field. If exploited, this Stored Cross-Site Scripting (XSS) vulnerability can lead to admin account takeover and the creation of persistent backdoors, compromising the entire WordPress site.

CVE-2024-8758 – Quiz and Survey Master (QSM) – Stored XSS to Admin Account Creation – POC

CVE-2024-8758 – Quiz and Survey Master (QSM) – Stored XSS to Admin Account Creation – POC

CVE-2024-8758 represents a serious vulnerability found in the Quiz and Survey Master (QSM) plugin, a popular WordPress plugin used to create quizzes and surveys, with over 50,000 installations. The flaw allows contributors to inject malicious JavaScript (JS) code into the plugin’s settings, leading to Stored Cross-Site Scripting (XSS) attacks. This can escalate into admin account takeover or the creation of persistent backdoors, enabling attackers to maintain long-term control over the WordPress site.

CVE-2024-8493 – The Events Calendar – Stored XSS to backdoor creation – POC

CVE-2024-8493 – The Events Calendar – Stored XSS to backdoor creation – POC

CVE-2024-8493 is a critical vulnerability identified in The Events Calendar plugin, a widely used WordPress plugin with over 700,000 installations. The vulnerability allows attackers with editor-level access to inject malicious JavaScript (JS) into the plugin’s settings, leading to account takeovers and backdoor creation. Improper input sanitization, particularly in the “Data time separator” field, exposes WordPress sites to this Stored XSS attack, potentially compromising the entire website.

CVE-2024-8619 – Ajax Search Lite – Stored XSS to backdoor creation – POC

CVE-2024-8619 – Ajax Search Lite – Stored XSS to backdoor creation – POC

CVE-2024-8619 exposes a serious Stored Cross-Site Scripting (XSS) vulnerability in the Ajax Search Lite plugin, a widely used search enhancement plugin with over 100,000 installations. This vulnerability allows attackers, specifically users with editor-level permissions, to inject malicious JavaScript (JS) into the plugin’s settings. Once exploited, the attacker can create backdoors and take over admin accounts, leading to full control of the WordPress site. The issue lies in improper input sanitization within the plugin’s “image width” field, which can be manipulated to execute malicious scripts.