CVE-2024-13851
CVSS 3.1 Score 4.8 of 10 (medium)
Details
Published Feb 28, 2025
Updated: Mar 6, 2025
CWE ID 79
Summary
CVE-2024-13851 is a Stored Cross-Site Scripting vulnerability affecting the Modal Portfolio plugin for WordPress. This issue, present in all versions up to 1.7.4.2, compromises input sanitization and output escaping, allowing authenticated attackers with Administrator-level access to inject malicious scripts. These scripts execute whenever a user accesses an injected page. The vulnerability is particularly concerning for multi-site installations and instances where unfiltered_html has been disabled.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.