CVE-2024-13898
CVSS 3.1 Score 4.4 of 10 (medium)
Details
Summary
CVE-2024-13898 is a Stored Cross-Site Scripting vulnerability affecting the Simple Banner plugin for WordPress. The flaw, present in all versions up to 3.0.5, permits authenticated attackers with administrator-level access to inject arbitrary web scripts into pages. This vulnerability is significant as it can lead to the execution of malicious code whenever a user accesses an injected page. The risk is elevated for multi-site installations and installations where unfiltered_html has been disabled. The root cause of this issue lies in insufficient input sanitization and output escaping within the plugin's admin settings.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.