« Volver al listado

CVE-2024-6158

Estado: AnalizadaMedia (4.8)—

The Category Posts Widget WordPress plugin before 4.9.17, term-and-category-based-posts-widget WordPress plugin before 4.9.13 does not validate and escape some of its "Category Posts" widget settings before outputting them back in a page/post where the Widget is embed, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (2)

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2024-6158",
  "cveTags": [],
  "metrics": {
    "ssvcV203": [
      {
        "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
        "ssvcData": {
          "id": "CVE-2024-6158",
          "role": "CISA Coordinator",
          "options": [
            {
              "exploitation": "poc"
            },
            {
              "automatable": "no"
            },
            {
              "technicalImpact": "partial"
            }
          ],
          "version": "2.0.3",
          "timestamp": "2024-08-13T14:18:52.873395Z"
        }
      }
    ],
    "cvssMetricV31": [
      {
        "type": "Secondary",
        "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
        "cvssData": {
          "scope": "CHANGED",
          "version": "3.1",
          "baseScore": 4.8,
          "attackVector": "NETWORK",
          "baseSeverity": "MEDIUM",
          "vectorString": "CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N",
          "integrityImpact": "LOW",
          "userInteraction": "REQUIRED",
          "attackComplexity": "LOW",
          "availabilityImpact": "NONE",
          "privilegesRequired": "HIGH",
          "confidentialityImpact": "LOW"
        },
        "impactScore": 2.7,
        "exploitabilityScore": 1.7
      }
    ]
  },
  "affected": [
    {
      "source": "contact@wpscan.com",
      "affectedData": [
        {
          "vendor": "Unknown",
          "product": "Category Posts Widget",
          "versions": [
            {
              "status": "affected",
              "version": "0",
              "lessThan": "4.9.17",
              "versionType": "semver"
            }
          ],
          "defaultStatus": "unaffected"
        },
        {
          "vendor": "Unknown",
          "product": "term-and-category-based-posts-widget",
          "versions": [
            {
              "status": "affected",
              "version": "0",
              "lessThan": "4.9.13",
              "versionType": "semver"
            }
          ],
          "defaultStatus": "unaffected"
        }
      ]
    },
    {
      "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
      "affectedData": [
        {
          "cpes": [
            "cpe:2.3:a:tiptoppress:category_posts:*:*:*:*:*:*:*:*"
          ],
          "vendor": "tiptoppress",
          "product": "category_posts",
          "versions": [
            {
              "status": "affected",
              "version": "0",
              "lessThan": "4.9.17",
              "versionType": "custom"
            }
          ],
          "defaultStatus": "unknown"
        },
        {
          "cpes": [
            "cpe:2.3:a:tiptoppress:term-and-category-based-posts:*:*:*:*:*:*:*:*"
          ],
          "vendor": "tiptoppress",
          "product": "term-and-category-based-posts",
          "versions": [
            {
              "status": "affected",
              "version": "0",
              "lessThan": "4.9.13",
              "versionType": "custom"
            }
          ],
          "defaultStatus": "unknown"
        }
      ]
    }
  ],
  "published": "2024-08-12T13:38:38.913",
  "references": [
    {
      "url": "https://wpscan.com/vulnerability/8adb219f-f0a6-4e87-8626-db26e300c220/",
      "tags": [
        "Exploit",
        "Third Party Advisory"
      ],
      "source": "contact@wpscan.com"
    }
  ],
  "vulnStatus": "Analyzed",
  "weaknesses": [
    {
      "type": "Primary",
      "source": "nvd@nist.gov",
      "description": [
        {
          "lang": "en",
          "value": "CWE-79"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "The Category Posts Widget WordPress plugin before 4.9.17, term-and-category-based-posts-widget WordPress plugin before 4.9.13 does not validate and escape some of its \"Category Posts\" widget settings before outputting them back in a page/post where the Widget is embed, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)"
    },
    {
      "lang": "es",
      "value": "El complemento Category Posts Widget de WordPress anterior a 4.9.17, el complemento term-and-category-based-posts-widget de WordPress anterior a 4.9.13 no valida ni escapa algunas de las configuraciones del widget de \"Publicaciones de categoría\" antes de devolverlas a una página/ publicar donde está incrustado el widget, lo que podría permitir a usuarios con privilegios elevados, como el administrador, realizar ataques de Cross-Site Scripting Almacenado incluso cuando la capacidad unfiltered_html no está permitida (por ejemplo, en una configuración multisitio)."
    }
  ],
  "lastModified": "2026-06-17T08:17:24.213",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:a:tiptoppress:term_and_category_based_posts_widget:*:*:*:*:*:wordpress:*:*",
              "vulnerable": true,
              "matchCriteriaId": "77D5B529-F547-4CF8-BDEC-D891F2C94255",
              "versionEndExcluding": "4.9.13"
            },
            {
              "criteria": "cpe:2.3:a:zephyrwest:category_posts_widget:*:*:*:*:*:wordpress:*:*",
              "vulnerable": true,
              "matchCriteriaId": "A86EACBA-CFF0-49C6-B436-42C20C964C8E",
              "versionEndExcluding": "4.9.17"
            }
          ],
          "operator": "OR"
        }
      ]
    }
  ],
  "sourceIdentifier": "contact@wpscan.com"
}