PT-2026-36299 · WordPress · Wordpress

Asaf Mozes

·

Published

2026-05-01

·

Updated

2026-05-01

·

CVE-2024-13362

CVSS v3.1

6.1

Medium

VectorAV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions WordPress plugins and themes (affected versions not specified)
Description Multiple plugins and themes for WordPress are susceptible to Reflected Cross-Site Scripting, a flaw where an application includes untrusted data in a web page without proper validation. This occurs due to insufficient input sanitization and output escaping involving the url parameter. Unauthenticated attackers can exploit this to inject arbitrary web scripts into pages, which execute when a user is tricked into clicking a malicious link.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

XSS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2024-13362

Affected Products

Wordpress