PT-2024-22695 · WordPress · Agca Wordpress Plugin

Cybersecdexter

+1

·

Published

2024-04-25

·

Updated

2025-05-14

·

CVE-2024-2907

CVSS v3.1

6.8

Medium

VectorAV:N/AC:L/PR:L/UI:R/S:U/C:H/I:L/A:L
Name of the Vulnerable Software and Affected Versions AGCA WordPress plugin versions prior to 7.2.2
Description The issue allows high privilege users, such as admins, to perform Stored Cross-Site Scripting attacks. This is possible because some settings are not properly sanitised and escaped, and this can occur even when the unfiltered html capability is disallowed, for example in a multisite setup.
Recommendations For versions prior to 7.2.2, update to version 7.2.2 or later to resolve the issue.

Exploit

Fix

XSS

Weakness Enumeration

Related Identifiers

CVE-2024-2907

Affected Products

Agca Wordpress Plugin