CVE-2024-13334
CVSS 3.1 Score 6.1 of 10 (medium)
Details
Published Jan 15, 2025
CWE ID 79
Summary
CVE-2024-13334: A Reflected Cross-Site Scripting (XSS) vulnerability has been identified in the Car Demon plugin for WordPress. This issue, affecting versions up to 1.8.1, arises due to inadequate input sanitization and output escaping in the 'search_condition' parameter. An attacker can exploit this flaw by injecting malicious scripts, which are then executed when an unsuspecting user clicks on a specially crafted link, potentially leading to unauthorized data access or further system compromise.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.