MEDIUM
Multiple Plugins <= (Various Versions) - Reflected Cross-Site Scripting via cminds_free_guide Shortcode
Published Nov 26, 2024
6.1
MEDIUMCVSS 3.1
EPSS 0.60%
Description
Multiple plugins for WordPress are vulnerable to Reflected Cross-Site Scripting via the cminds_free_guide shortcode in various versions due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a link.
Affected products
- Vendor Creativemindssolutions Product CM Business Directory – Optimise and showcase local business Defaultunaffected
- Version 0StatusaffectedConstraints<=1.4.1
- Version
- Vendor Creativemindssolutions Product CM E-Mail Blacklist – Simple email filtering for safer registration Defaultunaffected
- Version 0StatusaffectedConstraints<=1.5.3
- Version
- Vendor Creativemindssolutions Product CM Pop-Up – Create engaging popups to capture attention and boost interaction Defaultunaffected
- Version 0StatusaffectedConstraints<=1.7.5
- Version
-
- Version 0StatusaffectedConstraints<=4.3.11
- Version
-
- Version 0StatusaffectedConstraints<=1.2.1
- Version 0StatusaffectedConstraints<=1.4.2
- Version 0StatusaffectedConstraints<=1.8.2
- Version
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
| Vendor | Product | Default status | Versions | ||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| Creativemindssolutions | CM Business Directory – Optimise and showcase local business | unaffected |
| ||||||||||||
| Creativemindssolutions | CM E-Mail Blacklist – Simple email filtering for safer registration | unaffected |
| ||||||||||||
| Creativemindssolutions | CM Pop-Up – Create engaging popups to capture attention and boost interaction | unaffected |
| ||||||||||||
| Creativemindssolutions | CM Tooltip Glossary | unaffected |
| ||||||||||||
| Creativemindssolutions | n/a | unaffected |
|
No data.
No data.
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
No remediation recorded yet.
Weaknesses (1)
References (16)
- https://plugins.trac.wordpress.org/browser/cm-business-directory/trunk/package/cminds-free.php#L1465
- https://plugins.trac.wordpress.org/browser/cm-email-blacklist/trunk/package/cminds-free.php#L1465
- https://plugins.trac.wordpress.org/browser/cm-header-footer-script-loader/trunk/package/cminds-free.php#L1465
- https://plugins.trac.wordpress.org/browser/cm-on-demand-search-and-replace/trunk/package/cminds-free.php#L1469
- https://plugins.trac.wordpress.org/browser/cm-pop-up-banners/trunk/package/cminds-free.php#L1471
- https://plugins.trac.wordpress.org/browser/cm-video-lesson-manager/trunk/package/cminds-free.php#L1465
- https://plugins.trac.wordpress.org/browser/enhanced-tooltipglossary/trunk/package/cminds-free.php#L1465
- https://plugins.trac.wordpress.org/changeset/3191536/
- https://plugins.trac.wordpress.org/changeset/3192354/
- https://plugins.trac.wordpress.org/changeset/3192381/
- https://plugins.trac.wordpress.org/changeset/3192416/
- https://plugins.trac.wordpress.org/changeset/3192808/
- https://plugins.trac.wordpress.org/changeset/3193808/
- https://plugins.trac.wordpress.org/changeset/3194393/
- https://wordpress.org/plugins/cm-pop-up-banners/#developers
- https://www.wordfence.com/threat-intel/vulnerabilities/id/db759c60-9ce9-407d-8d1f-cbbfd09759d5?source=cve
Change history (0)
No recorded changes yet.
Sources
CVE.org / MITRE
Status PUBLISHED
Assigner Wordfence
Published Nov 26, 2024
Updated Apr 8, 2026
Reserved Nov 14, 2024
Link CVE-2024-11202
CISA Vulnrichment
Updated Nov 26, 2024