CVE-2024-13515

CVSS 3.1 Score 6.1 of 10 (medium)

Details

Published Jan 18, 2025
CWE ID 79

Summary

CVE-2024-13515 is a Reflected Cross-Site Scripting (XSS) vulnerability affecting the Image Source Control Lite plugin for WordPress. The issue lies in the insufficient input sanitization and output escaping of the 'path' parameter. Unauthenticated attackers can exploit this vulnerability by injecting arbitrary web scripts which can execute if a user is tricked into performing a specific action, such as clicking on a malicious link. All versions of the plugin up to and including 2.28.0 are affected. Users are encouraged to update to the latest version or disable the plugin as a temporary measure until a patch is available.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share