CVE-2024-13221

CVSS 3.1 Score 6.1 of 10 (medium)

Details

Published Jan 31, 2025
CWE ID 79

Summary

CVE-2024-13221: The Fantastic ElasticSearch WordPress plugin, prior to version 4.1.0, fails to sanitize and escape user input before displaying it on webpages. attackers can exploit this Reflected Cross-Site Scripting (XSS) vulnerability to inject malicious scripts, potentially gaining unauthorized access to accounts, particularly those with administrative privileges.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share