CVE-2024-22307 is a Reflected Cross-site Scripting (XSS) vulnerability found in WP Lab's WP-Lister Lite for eBay plugin, affecting versions up to and including 3.5.7. This flaw stems from improper neutralization of input during web page generation, allowing attackers to inject malicious scripts. Rated with a CVSS score of 6.1 (Medium), the vulnerability has a low attack complexity and requires user interaction (UI:R) for successful exploitation. A successful attack could lead to limited impact on confidentiality and integrity (C:L/I:L), such as session hijacking or defacement. Currently, there is no evidence of active exploitation, nor are there publicly available exploit modules in Metasploit, Nuclei, or ExploitDB. The vulnerability has garnered minimal community discussion and media coverage, indicating a low level of public awareness or concern at this time.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 0, <= 3.5.7CPE match | cpe:2.3:a:wplab:wp-lister_lite_for_ebay:*:*:*:*:*:wordpress:*:* | ||
<= 3.5.7CPE matchmatch criteria | cpe:2.3:a:wplab:wp-lister_lite_for_ebay:*:*:*:*:*:wordpress:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.