CVE-2024-13863

CVSS 3.1 Score 7.1 of 10 (high)

Details

Published Mar 25, 2025
Updated: Mar 27, 2025

Summary

CVE-2024-13863 is a Reflected Cross-Site Scripting (XSS) vulnerability affecting the Stylish Google Sheet Reader WordPress plugin before version 4.1. Maliciously crafted input is not properly sanitized or escaped by the plugin, allowing an attacker to inject and execute malicious scripts in the context of a user visiting the affected page. High privilege users, including admins, are at risk of being targeted.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share