CVE-2024-24713
CVSS 3.1 Score 5.4 of 10 (medium)
Details
Summary
CVE-2024-24713 is a Cross-site Scripting (XSS) vulnerability affecting the WP Auto Listings Auto Listings – Car Listings & Car Dealership Plugin for WordPress, from version n/a through 2.6.5. An attacker can exploit this improper neutralization of input during web page generation issue to inject malicious scripts into the plugin, resulting in unintended execution of code in users' browsers. This could potentially lead to unauthorized access, data theft, or manipulation of the affected WordPress site. It is essential to update the plugin to the latest version as soon as possible to mitigate this risk.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.