CVE-2024-13413
CVSS 3.1 Score 6.1 of 10 (medium)
Details
Published Mar 11, 2025
CWE ID 79
Summary
CVE-2024-13413 is a Reflected Cross-Site Scripting (XSS) vulnerability affecting the ProductDyno plugin for WordPress. In versions up to 1.0.24, insufficient input sanitization and output escaping have left the 'res' parameter open to exploitation. Unauthenticated attackers can inject arbitrary web scripts, which may execute if a user is tricked into taking certain actions like clicking on a malicious link. This vulnerability shares similarities with CVE-2025-22320, but the exact relationship between the two remains to be determined.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.