Home
Trends
Vulnerabilities
News
Researchers
Why dbugs?

Aprilliar

#52730of 53,624
3.5Total CVSS
Vulnerabilities · 1
PT-2025-12754
3.5
2025-03-25
WordPress · Afi Wordpress Plugin · CVE-2024-13122
**Name of the Vulnerable Software and Affected Versions** AFI WordPress plugin versions prior to 1.100.0 **Description** The issue allows high privilege users, such as admins, to perform Stored Cross-Site Scripting attacks. This can occur even when the unfiltered html capability is disallowed, for example in a multisite setup. The problem arises because some settings are not properly sanitised and escaped. **Recommendations** For versions prior to 1.100.0, update to version 1.100.0 or later to resolve the issue. As a temporary workaround, consider restricting the ability of high privilege users to access and modify the plugin's settings until the update can be applied.