CVE-2024-13380

CVSS 3.1 Score 6.4 of 10 (medium)

Details

Published Jan 30, 2025
Updated: Feb 18, 2025
CWE ID 79

Summary

CVE-2024-13380 is a Stored Cross-Site Scripting (XSS) vulnerability affecting the Alex Reservations: Smart Restaurant Booking plugin for WordPress. This issue, present in versions 2.0.5 and below, stems from insufficient input sanitization and output escaping on user-supplied attributes in the 'rr_form' shortcode. Consequently, authenticated attackers with contributor-level access or higher can inject malicious web scripts, which will execute whenever an unsuspecting user accesses a manipulated page. This could lead to serious security implications, including data theft or unauthorized system access. It is imperative that users of the Alex Reservations plugin upgrade to the latest, secure version as soon as possible.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share