Cross-site scripting vulnerability exists in My WP Customize Admin/Frontend versions prior to ver 1.24.1. If a malicious administrative user customizes the administrative page with some malicious contents, an arbitrary script may be executed on the web browser of the other users who are accessing the page.
Metrics
Affected Vendors & Products
References
History
Sun, 13 Jul 2025 13:45:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Metrics |
epss
|
epss
|
Tue, 17 Dec 2024 15:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Metrics |
ssvc
|
Tue, 17 Dec 2024 05:00:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | Cross-site scripting vulnerability exists in My WP Customize Admin/Frontend versions prior to ver 1.24.1. If a malicious administrative user customizes the administrative page with some malicious contents, an arbitrary script may be executed on the web browser of the other users who are accessing the page. | |
Weaknesses | CWE-79 | |
References |
| |
Metrics |
cvssV3_0
|

Status: PUBLISHED
Assigner: jpcert
Published: 2024-12-17T04:43:53.952Z
Updated: 2024-12-17T14:43:59.237Z
Reserved: 2024-12-11T00:29:42.949Z
Link: CVE-2024-55864

Updated: 2024-12-17T14:43:52.910Z

Status : Received
Published: 2024-12-17T05:15:09.937
Modified: 2024-12-17T05:15:09.937
Link: CVE-2024-55864

No data.