CVE-2024-12440

CVSS 3.1 Score 6.4 of 10 (medium)

Details

Published Jan 7, 2025
CWE ID 79

Summary

CVE-2024-12440 is a Stored Cross-Site Scripting (XSS) vulnerability affecting the Candifly plugin for WordPress. This issue, present in versions up to and including 1.0.6, allows authenticated attackers with contributor-level access or higher to inject malicious web scripts. The shortcoming lies in the plugin's insufficient input sanitization and output escaping of user-supplied attributes within the 'candifly' shortcode. Consequently, any page containing an injected shortcode will execute the injected scripts each time a user visits it.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share