CVE-2024-13610

CVSS 3.1 Score 4.8 of 10 (medium)

Details

Published Apr 15, 2025
Updated: Apr 29, 2025
CWE ID 79

Summary

CVE-2024-13610 is a vulnerability affecting the Simple Social Media Share Buttons WordPress plugin before version 6.0.0. This issue allows high privilege users, such as admins, to execute stored Cross-Site Scripting (XSS) attacks, bypassing the unfiltered_html capability restriction. The plugin does not properly sanitize and escape some settings, making it susceptible to these attacks. In multisite setups, this vulnerability could pose a significant security risk.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share