CVE-2024-6792 is a low-severity vulnerability affecting the WP ULike WordPress plugin prior to version 4.7.2.1, where it fails to properly sanitize user display names on public pages. This flaw, categorized as CWE-79 (Improper Neutralization of Input During Web Page Generation), carries a CVSS score of 3.5, indicating a low impact with potential for limited confidentiality and integrity compromise. Exploitation requires high privileges and user interaction, but its low EPSS score and lack of active exploitation, public exploit code, or community discussion suggest minimal current risk.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 4.7.2.1CPE matchmatch criteria | cpe:2.3:a:technowich:wp_ulike:*:*:*:*:*:wordpress:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:U/C:L/I:L/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.2 Bluesky, 0.0 Mastodon, and 0.0 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.