CVE-2024-9771

CVSS 3.1 Score 3.5 of 10 (low)

Details

Published Apr 28, 2025
Updated: Apr 29, 2025
CWE ID 79

Summary

CVE-2024-9771 is a vulnerability affecting the WP-Recall WordPress plugin before version 16.26.12. This issue permits high privilege users, including administrators, to execute Stored Cross-Site Scripting (XSS) attacks. Despite the unfiltered_html capability being disallowed, particularly in multisite setups, the plugin fails to sanitize and escape some of its settings. This flaw could lead to unintended code execution and potential data theft or site takeover. Users are encouraged to update to the latest plugin version to mitigate the risk.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share