CVE-2024-55864 Information

Description

Cross-site scripting vulnerability exists in My WP Customize Admin/Frontend versions prior to ver 1.24.1. If a malicious administrative user customizes the administrative page with some malicious contents an arbitrary script may be executed on the web browser of the other users who are accessing the page.

Reference

https://jvn.jp/en/vu/JVNVU90748215/ https://mywpcustomize.com/update-history-my-wp-customize-admin-frontend-1-24-1/ https://wordpress.org/plugins/my-wp/#developers

Share on: