CVE-2024-13549
CVSS 3.1 Score 5.4 of 10 (medium)
Details
Summary
CVE-2024-13549 is a Stored Cross-Site Scripting (XSS) vulnerability affecting the All Bootstrap Blocks plugin for WordPress. This issue allows authenticated attackers with Contributor-level access or higher to inject arbitrary web scripts into the "Accordion" widget in all versions up to 1.3.26. The vulnerable plugin fails to properly sanitize user input and escape output, resulting in the execution of injected scripts whenever a user visits an affected page. This vulnerability poses a significant risk to websites using the All Bootstrap Blocks plugin and is recommended that users upgrade to the latest version to mitigate the threat.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.