CVE-2024-13097
CVSS 3.1 Score 5.4 of 10 (medium)
Details
Summary
CVE-2024-13097 is a Reflected Cross-Site Scripting (XSS) vulnerability affecting the WP Finance WordPress plugin before version 1.3.7. This issue stems from the plugin's failure to sanitize and escape user input before displaying it on the page. Malicious actors can exploit this vulnerability by injecting malicious scripts into a webpage, which could potentially be executed in the context of high privilege users such as administrators. This could result in data theft, unauthorized account access, or other malicious activities. To mitigate this risk, users are advised to update their WP Finance plugin to the latest version or consider disabling the plugin if it's no longer needed.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.