CVE-2024-13625

CVSS 3.1 Score 7.1 of 10 (high)

Details

Published Feb 17, 2025
Updated: Feb 19, 2025

Summary

CVE-2024-13625 is a Reflected Cross-Site Scripting (XSS) vulnerability affecting the Tube Video Ads Lite WordPress plugin before version 1.5.8. The issue lies in the plugin's failure to sanitize and escape a user input parameter, allowing attackers to inject malicious scripts into web pages viewed by high-privilege users, such as administrators. Successful exploitation could lead to unauthorized access and data theft. Users are advised to update the plugin or temporarily remove it from their WordPress installations until a patch is released.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share