CVE-2024-13657

CVSS 3.1 Score 6.4 of 10 (medium)

Details

Published Feb 19, 2025
CWE ID 79

Summary

CVE-2024-13657 is a stored Cross-Site Scripting (XSS) vulnerability affecting the Store Locator Widget plugin for WordPress. The issue lies in the plugin's 'storelocatorwidget' shortcode, which does not adequately sanitize or escape user-supplied attributes. This weakness allows attackers, who have contributor-level access or higher, to inject malicious web scripts into pages. Once injected, these scripts will execute whenever a user accesses the affected page. The vulnerability exists in all versions of the plugin up to and including 20200131.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share