CVE-2024-8056: Mm-Breaking News Project Mm-Breaking News
Medium severity, CVSS 6.1. EPSS: 0.3% chance of exploitation in the next 30 days.
The MM-Breaking News WordPress plugin through 0.7.9 does not escape the $_SERVER['REQUEST_URI'] parameter before outputting it back in an attribute, which could lead to Reflected Cross-Site Scripting in old web browsers
Affected products
- Mm-Breaking News Project Mm-Breaking News: up to and including 0.7.9
Published 2024-09-12. Last modified 2026-06-17.