RULE(RULE ID:338022)

Rule General Information
Release Date: 2024-05-16
Rule Name: WordPress Alemha Watermarker 1.3.1 Cross Site Scripting Vulnerability
Severity:
CVE ID:
Rule Protection Details
Description: WordPress is a blogging platform developed using PHP language. The platform supports to set up personal blog website on PHP and MySQL server. Version 1.3.1 of the WordPress Alemha Watermarker plugin has a cross-site scripting vulnerability that allows a remote attacker to inject arbitrary Web script or HTML into the atermark_title parameter by sending a request to /wp-admin/post.php.
Impact: An attacker can conduct a cross-site scripting attack to inject malicious client-side scripts into web pages viewed by other users, or to bypass access controls such as the same-origin policy, if affected version is installed.
Affected OS: Windows, Linux, Others
Reference:
Solutions
Please contact the software vendor to update the software patch.