CVE-2024-12682

CVSS 3.1 Score 6.1 of 10 (medium)

Details

Published Mar 25, 2025
Updated: Mar 27, 2025

Summary

CVE-2024-12682 is a vulnerability affecting the Smart Maintenance Mode plugin for WordPress before version 1.5.2. This issue allows high privilege users, including admins, to execute Stored Cross-Site Scripting attacks. Despite the disallowing of the unfiltered_html capability, the plugin fails to sanitize and escape certain settings, making them vulnerable to such attacks. This can potentially lead to serious security consequences, including data breaches or unauthorized access to user accounts. Users are strongly advised to update to the latest version of the plugin to mitigate this risk.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share