CVE-2024-13559
CVSS 3.1 Score 6.4 of 10 (medium)
Details
Summary
CVE-2024-13559 is a Stored Cross-Site Scripting (XSS) vulnerability affecting the TemplatesNext ToolKit plugin for WordPress. The issue lies in the 'tx_woo_wishlist_table' shortcode of the plugin, which fails to properly sanitize and escape user-supplied attributes. This allows authenticated attackers with contributor-level access or higher to inject malicious scripts into pages. The vulnerability exists in all versions of the plugin up to and including 3.2.9. Successful exploitation of this weakness can result in the execution of arbitrary web scripts whenever an injected page is accessed.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.