CVE-2024-12500
CVSS 3.1 Score 6.4 of 10 (medium)
Details
Summary
CVE-2024-12500 is a Stored Cross-Site Scripting (XSS) vulnerability affecting the Philantro – Donations and Donor Management plugin for WordPress. This issue, present in all versions up to 5.2, allows authenticated attackers with contributor-level access or higher to inject malicious scripts into the plugin's shortcodes, such as 'donate'. The unsanitized and improperly escaped user-supplied attributes in these shortcodes enable the attacker to execute their scripts whenever a user accesses an injected page, potentially leading to unintended actions or information disclosure.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.