CVE-2024-13385
CVSS 3.1 Score 6.4 of 10 (medium)
Details
Summary
CVE-2024-13385 is a Stored Cross-Site Scripting (XSS) vulnerability affecting the JSM Screenshot Machine Shortcode plugin for WordPress. The issue, present in all versions up to 2.3.0, stems from insufficient input sanitization and output escaping on user-supplied attributes in the plugin's 'ssm' shortcode. This weakness allows authenticated attackers, with contributor-level access and above, to inject malicious web scripts into pages. Execution of these scripts occurs whenever a user accesses the injected page, posing a significant risk to the security and integrity of the affected WordPress website.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.