PT-2025-21437 · WordPress · Advance Post Prefix
Published
2025-05-15
·
Updated
2026-02-07
·
CVE-2024-12734
CVSS v3.1
6.1
Medium
| Vector | AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
Advance Post Prefix WordPress plugin versions through 1.1.1
Description
The Advance Post Prefix WordPress plugin does not properly sanitize and escape a parameter before displaying it, resulting in a Reflected Cross-Site Scripting issue. This could potentially be exploited against users with high privileges, such as administrators. The issue involves improper handling of input data, which allows an attacker to inject malicious scripts into the webpage. The vulnerable parameter is not explicitly identified.
Recommendations
Update the Advance Post Prefix WordPress plugin to a version later than 1.1.1.
Exploit
Fix
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Advance Post Prefix