CVE-2024-13898

CVSS 3.1 Score 4.4 of 10 (medium)

Details

Published Apr 4, 2025
Updated: Apr 7, 2025
CWE ID 79

Summary

CVE-2024-13898 is a Stored Cross-Site Scripting vulnerability affecting the Simple Banner plugin for WordPress. The flaw, present in all versions up to 3.0.5, permits authenticated attackers with administrator-level access to inject arbitrary web scripts into pages. This vulnerability is significant as it can lead to the execution of malicious code whenever a user accesses an injected page. The risk is elevated for multi-site installations and installations where unfiltered_html has been disabled. The root cause of this issue lies in insufficient input sanitization and output escaping within the plugin's admin settings.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share