← back
CVE-2024-4477

WP Logs Book <= 1.0.1 - Unauthenticated Stored XSS

CVSS 4.3 MEDIUMEPSS 0.3%
The WP Logs Book WordPress plugin through 1.0.1 does not sanitise and escape some of its log data before outputting them back in an admin dashboard, leading to an Unauthenticated Stored Cross-Site Scripting
CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:U/C:L/I:L/A:L
Affected products
Unknown · WP Logs Book

Want to know if your infrastructure is exposed to this?

Talk to TrueHacking →