CVE-2024-12749
CVSS 3.1 Score 7.1 of 10 (high)
Details
Published Jan 29, 2025
Summary
CVE-2024-12749 is a Reflected Cross-Site Scripting (XSS) vulnerability affecting the Competition Form WordPress plugin before version 2.0. The plugin fails to sanitize and escape user input before displaying it on the page, allowing an attacker to inject malicious scripts. This issue poses a significant risk to high privilege users, particularly admins, as they can be targeted with these scripts to gain unauthorized access or perform malicious actions within the WordPress environment.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.
Share