CVE-2024-13660
CVSS 3.1 Score 6.4 of 10 (medium)
Details
Summary
CVE-2024-13660 is a Stored Cross-Site Scripting (XSS) vulnerability affecting the Responsive Flickr Slideshow plugin for WordPress. This issue exists in all versions up to 2.6.1 due to insufficient input sanitization and output escaping on user-supplied attributes in the plugin's 'fshow' shortcode. Authenticated attackers with contributor-level access or higher can exploit this vulnerability to inject arbitrary web scripts, which will execute whenever a user accesses an injected page. Successful exploitation could lead to unintended website behavior or even data theft. Upgrading to the latest version of the plugin or disabling the plugin temporarily is recommended as a mitigation measure.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.
Affected Products
- Responsive Flickr Slideshow Plugin
Affected Vendors
- WordPress