CVE-2024-58305: Wondercms
High severity, CVSS 8.8. EPSS: 0.4% chance of exploitation in the next 30 days.
WonderCMS 4.3.2 contains a cross-site scripting vulnerability that allows attackers to inject malicious JavaScript through the module installation endpoint. Attackers can craft a specially designed XSS payload to install a reverse shell module and execute remote commands by tricking an authenticated administrator into accessing a malicious link.
Affected products
- Wondercms Wondercms: version 4.3.2 only
Published 2025-12-12. Last modified 2026-06-17.