CVE-2024-13551
CVSS 3.1 Score 5.4 of 10 (medium)
Details
Published Jan 25, 2025
Updated: Feb 5, 2025
CWE ID 79
Summary
CVE-2024-13551 is a stored Cross-Site Scripting (XSS) vulnerability affecting the ABC Notation plugin for WordPress. This issue, present in versions up to 6.1.3, stems from insufficient input sanitization and output escaping on user-supplied attributes within the plugin's 'abcjs' shortcode. As a result, authenticated attackers, including those with contributor-level access and above, can inject malicious web scripts. These scripts will execute whenever a user visits an injected page, posing a significant security risk.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.