CVE-2024-13221
CVSS 3.1 Score 6.1 of 10 (medium)
Details
Published Jan 31, 2025
CWE ID 79
Summary
CVE-2024-13221: The Fantastic ElasticSearch WordPress plugin, prior to version 4.1.0, fails to sanitize and escape user input before displaying it on webpages. attackers can exploit this Reflected Cross-Site Scripting (XSS) vulnerability to inject malicious scripts, potentially gaining unauthorized access to accounts, particularly those with administrative privileges.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.