PT-2025-9816 · WordPress · Staff Directory Plugin

Peter Thaleikis

·

Publicado

2025-03-05

·

Atualizado

2025-03-06

·

CVE-2024-13839

CVSS v3.1

6.1

Média

VetorAV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions The Staff Directory Plugin: Company Directory plugin for WordPress versions up to, and including, 4.3
Description The issue arises from the use of add query arg without proper escaping on the URL, leading to Reflected Cross-Site Scripting. This allows unauthenticated attackers to inject arbitrary web scripts into pages, which execute when a user performs a specific action, such as clicking on a link.
Recommendations For versions up to, and including, 4.3, update to a version that properly escapes URLs to prevent Reflected Cross-Site Scripting attacks.

Correção

XSS

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2024-13839

Produtos afetados

Staff Directory Plugin