CVE-2024-13352

CVSS 3.1 Score 7.1 of 10 (high)

Details

Published Feb 7, 2025

Summary

CVE-2024-13352 is a Reflected Cross-Site Scripting (XSS) vulnerability affecting the Legull WordPress plugin before version 1.2.3. The issue arises from the plugin's failure to sanitize and escape a user input parameter before displaying it on the page. An attacker can exploit this vulnerability by injecting malicious scripts into the input field, leading to the execution of arbitrary code in the user's browser when they view a specially crafted page. This vulnerability poses a significant risk to high-privilege users, such as administrators, as they can be targeted with these attacks and inadvertently compromise the entire WordPress site.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share