CVE-2024-13549

CVSS 3.1 Score 5.4 of 10 (medium)

Details

Published Jan 30, 2025
Updated: Jan 31, 2025
CWE ID 79

Summary

CVE-2024-13549 is a Stored Cross-Site Scripting (XSS) vulnerability affecting the All Bootstrap Blocks plugin for WordPress. This issue allows authenticated attackers with Contributor-level access or higher to inject arbitrary web scripts into the "Accordion" widget in all versions up to 1.3.26. The vulnerable plugin fails to properly sanitize user input and escape output, resulting in the execution of injected scripts whenever a user visits an affected page. This vulnerability poses a significant risk to websites using the All Bootstrap Blocks plugin and is recommended that users upgrade to the latest version to mitigate the threat.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share