CVE-2024-6810
CVSS 3.1 Score 4.4 of 10 (medium)
Details
Published Feb 26, 2025
CWE ID 79
Summary
CVE-2024-6810 is a Stored Cross-Site Scripting vulnerability affecting the Quiz Organizer plugin for WordPress. This issue, which arises from insufficient input sanitization and output escaping, allows authenticated attackers with administrator-level access to inject malicious scripts into pages. These scripts will execute when a user accesses an injected page, posing a security risk. Notably, this vulnerability only impacts multi-site installations and WordPress installations where unfiltered_html has been disabled.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.