CVE-2024-9771
CVSS 3.1 Score 3.5 of 10 (low)
Details
Published Apr 28, 2025
Updated: Apr 29, 2025
CWE ID 79
Summary
CVE-2024-9771 is a vulnerability affecting the WP-Recall WordPress plugin before version 16.26.12. This issue permits high privilege users, including administrators, to execute Stored Cross-Site Scripting (XSS) attacks. Despite the unfiltered_html capability being disallowed, particularly in multisite setups, the plugin fails to sanitize and escape some of its settings. This flaw could lead to unintended code execution and potential data theft or site takeover. Users are encouraged to update to the latest plugin version to mitigate the risk.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.