CVE-2024-13385

CVSS 3.1 Score 6.4 of 10 (medium)

Details

Published Jan 18, 2025
CWE ID 79

Summary

CVE-2024-13385 is a Stored Cross-Site Scripting (XSS) vulnerability affecting the JSM Screenshot Machine Shortcode plugin for WordPress. The issue, present in all versions up to 2.3.0, stems from insufficient input sanitization and output escaping on user-supplied attributes in the plugin's 'ssm' shortcode. This weakness allows authenticated attackers, with contributor-level access and above, to inject malicious web scripts into pages. Execution of these scripts occurs whenever a user accesses the injected page, posing a significant risk to the security and integrity of the affected WordPress website.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share