CVE-2024-13497

CVSS 3.1 Score 6.1 of 10 (medium)

Details

Published Mar 15, 2025
Updated: Mar 28, 2025
CWE ID 79
CWE ID 80

Summary

CVE-2024-13497 is a stored Cross-Site Scripting (XSS) vulnerability affecting the Tripetto plugin for WordPress, used for creating contact forms, surveys, and quizzes. Versions up to and including 8.0.9 are vulnerable due to inadequate input sanitization and output escaping during attachment uploads. This vulnerability enables unauthenticated attackers to inject malicious web scripts into uploaded files, causing these scripts to execute whenever a user accesses the affected page. Successful exploitation of this vulnerability could lead to data theft, user session hijacking, or even complete site takeover. It is recommended that users immediately update their plugins to the latest version to mitigate this risk.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share