CVE-2024-11889

Published Dec 14, 2024

Last updated 2 months ago

Overview

Description
The My IDX Home Search plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'homeasap-idx-search' shortcode in all versions up to, and including, 2.0.1 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
Source
security@wordfence.com
NVD status
Received

Risk scores

CVSS 3.1

Type
Primary
Base score
6.4
Impact score
2.7
Exploitability score
3.1
Vector string
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N
Severity
MEDIUM

Weaknesses

security@wordfence.com
CWE-79

Social media

Hype score
Not currently trending
  1. ๐Ÿšจ CVE-2024-11889 (Published: 2024-12-14) - High severity vulnerability in Homeasap. Affects specific versions of the plugin. Users are urged to update to the latest version to mitigate risks. For more details, check the code here: https://t.co/SkIw6iTn0f #WordPressSecurity

    @transilienceai

    18 Dec 2024

    16 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  2. ๐Ÿšจ CVE-2024-11889 (Published: 2024-12-14) - High severity vulnerability in Homeasap. Affects specific versions of the plugin. Remediation: Update to the latest version to mitigate risks. For more details, check the code here: https://t.co/SkIw6iTn0f #WordPress #Security

    @transilienceai

    18 Dec 2024

    21 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  3. ๐Ÿšจ CVE-2024-11889 (Published: 2024-12-14) - High severity vulnerability in Homeasap. Affects specific versions of the plugin. Ensure you update to the latest version to mitigate risks. For details, check the code here: https://t.co/SkIw6iTn0f #WordPress #Security

    @transilienceai

    18 Dec 2024

    20 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  4. ๐Ÿšจ CVE-2024-11889 (Published: 2024-12-14) - High severity vulnerability in Homeasap. Affects specific versions of the plugin. Ensure you update to the latest version to mitigate risks. For more details, check the code here: https://t.co/SkIw6iTn0f #WordPress #Security

    @transilienceai

    18 Dec 2024

    17 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  5. CVE-2024-11889 Stored Cross-Site Scripting in My IDX Home Search WordPress Plugin The ... https://t.co/7cpCar1VsE Vulnerability Notification: https://t.co/xhLrNnfyrO

    @VulmonFeeds

    14 Dec 2024

    67 Impressions

    1 Retweet

    1 Like

    1 Bookmark

    0 Replies

    0 Quotes