CVE-2024-13515
CVSS 3.1 Score 6.1 of 10 (medium)
Details
Summary
CVE-2024-13515 is a Reflected Cross-Site Scripting (XSS) vulnerability affecting the Image Source Control Lite plugin for WordPress. The issue lies in the insufficient input sanitization and output escaping of the 'path' parameter. Unauthenticated attackers can exploit this vulnerability by injecting arbitrary web scripts which can execute if a user is tricked into performing a specific action, such as clicking on a malicious link. All versions of the plugin up to and including 2.28.0 are affected. Users are encouraged to update to the latest version or disable the plugin as a temporary measure until a patch is available.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.