CVE-2024-13390
CVSS 3.1 Score 6.4 of 10 (medium)
Details
Published Feb 19, 2025
CWE ID 79
Summary
CVE-2024-13390: The ADFO plugin for WordPress, used in versions 1.9.1 and below, is found to have a Stored Cross-Site Scripting (XSS) vulnerability. This issue arises due to inadequate input sanitization and output escaping in the 'adfo_list' shortcode. Attackers with contributor-level access or above can exploit this flaw by injecting malicious scripts, which execute when a user accesses an affected page. This vulnerability poses a significant risk to websites using the plugin and should be addressed promptly by updating to a secure version.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.
Share