CVE-2024-13566

CVSS 3.1 Score 6.4 of 10 (medium)

Details

Published Jan 31, 2025
CWE ID 79

Summary

CVE-2024-13566 is a Stored Cross-Site Scripting (XSS) vulnerability affecting the WP DataTable plugin for WordPress. This issue, impacting versions 0.2.6 and below, permits authenticated attackers with Contributor-level access or higher to inject malicious scripts via the 'id' parameter. The lack of sufficient input sanitization and output escaping in the plugin facilitates the execution of these scripts whenever an affected user visits an injected page. This vulnerability poses a significant risk, as it allows attackers to manipulate website content and potentially steal user data.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share