← Back

CVE-2024-11638

nvd nist
Published: Mar 10, 2025Modified: Jun 17, 2026

JSON object

Loading...
8.8
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Exploitability: 2.8 / Impact: 5.9
Source: 134c704f-9b21-4f2e-91b3-4a467353bcc0 (Secondary)

Description

The Gtbabel WordPress plugin before 6.6.9 does not ensure that the URL to perform code analysis upon belongs to the blog which could allow unauthenticated attackers to retrieve a logged in user (such as admin) cookies by making them open a crafted URL as the request made to analysed the URL contains such cookies.

Affected (1)

Products: Gtbabel: Gtbabel
1 product
Gtbabel
Configuration A
1 vulnerable
Vulnerable SoftwareAffected Versions
Before 6.6.9

References (1)

Source: contact@wpscan.com
ExploitThird Party Advisory

Timeline

No history available yet.