{"id":"CVE-2024-10038","summary":"WP-Strava \u003c= 2.12.1 - Authenticated (Administrator+) Stored Cross-Site Scripting","details":"The WP-Strava plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 2.12.1 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level permissions and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. This only affects multi-site installations and installations where unfiltered_html has been disabled.","modified":"2026-07-15T01:48:59.809701191Z","published":"2024-11-13T02:02:33.697Z","database_specific":{"cna_assigner":"Wordfence","cwe_ids":["CWE-80"],"osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2024/10xxx/CVE-2024-10038.json"},"references":[{"type":"WEB","url":"https://github.com/cmanon/wp-strava/blob/5b9499dab0eeada3887e5b64cf471e7978147154/src/WPStrava/Auth.php#L92-L93"},{"type":"WEB","url":"https://www.wordfence.com/threat-intel/vulnerabilities/id/9f200526-890c-4a2a-9d8e-334443ef7e0b?source=cve"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2024/10xxx/CVE-2024-10038.json"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2024-10038"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/cmanon/wp-strava","events":[{"introduced":"0"},{"last_affected":"c4df4301ec3e3d87be21a0f9d31ff3bfa3bbaeb8"}],"database_specific":{"source":"AFFECTED_FIELD","extracted_events":[{"introduced":"0"},{"last_affected":"2.12.1"}]}}],"versions":["v2.12.1","v2.12.0","v2.11.1","v2.12.0-beta1","v2.11.0","v2.10.1","v2.10.0","v2.9.1","v2.9.0","v2.8.0","v2.7.0","2.7.0","v2.6.0","v2.5.1","v2.5.0","v2.4.0","v2.3.2","v2.3.1","v2.3.0","v2.2.0","v2.1.0","v2.0.1","v2.0.0","v1.7.2","v1.7.1","v1.7.0","v1.6.0","v1.5.1-rc3","v1.5.1-rc2","v1.5.1-rc1","v1.5.0","v1.4.3","v1.4.2","v1.4.1","v1.4.0","v1.3.0","v1.2.0","1.2.0","v1.1.1","v1.1","v0.62","v0.61"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2024-10038.json"}}],"schema_version":"1.7.5","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N"}]}