CVE-2024-39682

Source
https://cve.org/CVERecord?id=CVE-2024-39682
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2024-39682.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2024-39682
Aliases
  • GHSA-fx69-f77x-84gr
Published
2024-07-17T23:47:56.165Z
Modified
2026-03-14T12:34:47.911048Z
Severity
  • 6.4 (Medium) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:N/I:L/A:L CVSS Calculator
Summary
WordPress Cooked Plugin - Authenticated (Contributor+) HTML Injection via Recipe Excerpt
Details

Cooked is a recipe plugin for WordPress. The Cooked plugin for WordPress is vulnerable to HTML Injection in versions up to, and including, 1.7.15.4 due to insufficient input sanitization and output escaping. This vulnerability allows authenticated attackers with contributor-level access and above to inject arbitrary HTML in pages that will be shown whenever a user accesses a compromised page. This issue has been addressed in release version 1.8.0. Users are advised to upgrade. There are no known workarounds for this vulnerability.

Database specific
{
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2024/39xxx/CVE-2024-39682.json",
    "cwe_ids": [
        "CWE-116"
    ],
    "cna_assigner": "GitHub_M"
}
References

Affected packages

Git / github.com/xjsv/cooked

Affected ranges

Type
GIT
Repo
https://github.com/xjsv/cooked
Events
Introduced
0 Unknown introduced commit / All previous commits are affected
Fixed

Affected versions

v1.*
v1.7.14
v1.7.15.2
v1.7.15.3
v1.7.15.4

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2024-39682.json"