CVE-2024-13875
CVSS 3.1 Score 7.1 of 10 (high)
Details
Published Mar 20, 2025
Summary
CVE-2024-13875 is a Reflected Cross-Site Scripting (XSS) vulnerability affecting the WP-PManager WordPress plugin up to version 1.2. This issue allows an attacker to inject malicious scripts into a webpage viewed by other users, by exploiting the lack of sanitization and escaping of an input parameter. High privilege users, such as admins, are particularly at risk from this vulnerability. Successful exploitation could result in unauthorized access or data theft. Users are advised to update the plugin to the latest version to mitigate this risk.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.