CVE-2024-13799

CVSS 3.1 Score 6.4 of 10 (medium)

Details

Published Feb 19, 2025
CWE ID 79

Summary

CVE-2024-13799 is a stored Cross-Site Scripting (XSS) vulnerability affecting the User Private Files plugin for WordPress. The issue lies in the File Upload & Download Manager with Secure File Sharing component, which fails to properly sanitize and escape user input in the 'new-fldr-name' parameter. This flaw allows authenticated attackers, with Subscriber-level access and above, to inject malicious scripts into pages. Execution of these scripts occurs when any user accesses the affected pages, posing a significant security risk.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share