CVE-2024-13875

CVSS 3.1 Score 7.1 of 10 (high)

Details

Published Mar 20, 2025

Summary

CVE-2024-13875 is a Reflected Cross-Site Scripting (XSS) vulnerability affecting the WP-PManager WordPress plugin up to version 1.2. This issue allows an attacker to inject malicious scripts into a webpage viewed by other users, by exploiting the lack of sanitization and escaping of an input parameter. High privilege users, such as admins, are particularly at risk from this vulnerability. Successful exploitation could result in unauthorized access or data theft. Users are advised to update the plugin to the latest version to mitigate this risk.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share