cve,link,title,description,vendor,products,score,severity,epss,cisa,cisa_published,article,ransomware,exploited,poc,trended,trended_no_1,published,trended_score CVE-2024-9873,https://securityvulnerability.io/vulnerability/CVE-2024-9873,Sweden's Ruling Party Backs Investigative Journalist Over Government Censorship Claims,"The Community by PeepSo plugin for WordPress is exposed to a Stored Cross-Site Scripting vulnerability due to insufficient sanitization of inputs and escaping of outputs. When Markdown support is enabled, authenticated users with Subscriber-level access or higher can exploit this flaw by injecting malicious scripts into posts, comments, and profiles. These scripts can execute in the browsers of users accessing the affected pages, posing a serious risk to user data integrity and security.",Wordpress,"Community By Peepso – Social Network, Membership, Registration, User Profiles, Premium – Mobile App",5.4,MEDIUM,0.0004299999854993075,false,,false,false,false,,false,false,2024-10-16T05:31:56.035Z,0 CVE-2024-7618,https://securityvulnerability.io/vulnerability/CVE-2024-7618,Stored Cross-Site Scripting vulnerability in PeepSo's Social Network plugin,"The PeepSo plugin for WordPress is susceptible to Stored Cross-Site Scripting (XSS) attacks due to a lack of sufficient input sanitization and output escaping in the 'content' parameter. This vulnerability affects all versions of the plugin up to and including version 6.4.5.0 and can be exploited by authenticated attackers with administrator-level access. When triggered, the vulnerability allows attackers to embed malicious scripts in web pages, which execute whenever any user accesses those affected pages. The risk is elevated in multi-site installations and configurations where the unfiltered_html option is disabled, increasing the potential for unauthorized script execution.",Wordpress,"Community By Peepso – Social Network, Membership, Registration, User Profiles, Premium – Mobile App",4.8,MEDIUM,0.0006099999882280827,false,,false,false,false,,false,false,2024-09-10T07:30:04.499Z,0 CVE-2024-7655,https://securityvulnerability.io/vulnerability/CVE-2024-7655,Stored Cross-Site Scripting Vulnerability Affects PeepSo Community Multi-Site Installations,"The Community by PeepSo – Social Network, Membership, Registration, User Profiles plugin for WordPress is vulnerable to Stored Cross-Site Scripting in all versions up to, and including, 6.4.5.0 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level access, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. This only affects multi-site installations and installations where unfiltered_html has been disabled.",Wordpress,"Community By Peepso – Social Network, Membership, Registration, User Profiles, Premium – Mobile App",4.8,MEDIUM,0.0006099999882280827,false,,false,false,false,,false,false,2024-09-10T07:30:03.793Z,0