CVE-2024-12513

CVSS 3.1 Score 6.4 of 10 (medium)

Details

Published Dec 18, 2024
CWE ID 79

Summary

CVE-2024-12513 is a stored Cross-Site Scripting (XSS) vulnerability affecting the Contests by Rewards Fuel plugin for WordPress. This issue exists in all versions up to and including 2.0.65 due to insufficient sanitization and output escaping of user-supplied attributes in the 'RF_CONTEST' shortcode. Attackers with contributor-level access or higher can exploit this vulnerability to inject arbitrary web scripts that execute whenever a user accesses an injected page, posing a significant threat to site integrity and user security.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share