CVE-2024-13334

CVSS 3.1 Score 6.1 of 10 (medium)

Details

Published Jan 15, 2025
CWE ID 79

Summary

CVE-2024-13334: A Reflected Cross-Site Scripting (XSS) vulnerability has been identified in the Car Demon plugin for WordPress. This issue, affecting versions up to 1.8.1, arises due to inadequate input sanitization and output escaping in the 'search_condition' parameter. An attacker can exploit this flaw by injecting malicious scripts, which are then executed when an unsuspecting user clicks on a specially crafted link, potentially leading to unauthorized data access or further system compromise.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share