CVE-2024-13413

CVSS 3.1 Score 6.1 of 10 (medium)

Details

Published Mar 11, 2025
CWE ID 79

Summary

CVE-2024-13413 is a Reflected Cross-Site Scripting (XSS) vulnerability affecting the ProductDyno plugin for WordPress. In versions up to 1.0.24, insufficient input sanitization and output escaping have left the 'res' parameter open to exploitation. Unauthenticated attackers can inject arbitrary web scripts, which may execute if a user is tricked into taking certain actions like clicking on a malicious link. This vulnerability shares similarities with CVE-2025-22320, but the exact relationship between the two remains to be determined.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share