CVE-2024-13669
CVSS 3.1 Score 6.1 of 10 (medium)
Details
Summary
CVE-2024-13669 is a Reflected Cross-Site Scripting (XSS) vulnerability affecting the CalendApp WordPress plugin before version 1.1. This issue allows an attacker to inject malicious scripts into a webpage by exploiting the lack of proper sanitization and escaping of user-supplied data. High privilege users, such as admins, are particularly at risk due to their elevated access level. Successful exploitation of this vulnerability could result in the theft or modification of sensitive data or even the complete takeover of the affected WordPress site. It is highly recommended that users of the CalendApp plugin upgrade to the latest version to mitigate this risk.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.