Home
Trends
Vulnerabilities
News
Researchers
Why dbugs?

Ayush Juneja

#41207of 53,632
6.5Total CVSS
Vulnerabilities · 1
PT-2024-20342
6.5
2024-06-15
WordPress · Website Content In Page/Post · CVE-2024-2430
**Name of the Vulnerable Software and Affected Versions** Website Content in Page or Post WordPress plugin versions prior to 2024.04.09 **Description** The issue concerns the Website Content in Page or Post WordPress plugin, which does not properly validate and escape certain shortcode attributes before outputting them in a page or post. This could allow users with the contributor role or higher to perform Stored Cross-Site Scripting attacks. **Recommendations** For versions prior to 2024.04.09, update to version 2024.04.09 or later to resolve the issue. As a temporary workaround, consider restricting the use of shortcodes to minimize the risk of exploitation.