PT-2026-36299 · WordPress · Wordpress
Asaf Mozes
·
Published
2026-05-01
·
Updated
2026-05-01
·
CVE-2024-13362
CVSS v3.1
6.1
Medium
| Vector | AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
WordPress plugins and themes (affected versions not specified)
Description
Multiple plugins and themes for WordPress are susceptible to Reflected Cross-Site Scripting, a flaw where an application includes untrusted data in a web page without proper validation. This occurs due to insufficient input sanitization and output escaping involving the
url parameter. Unauthenticated attackers can exploit this to inject arbitrary web scripts into pages, which execute when a user is tricked into clicking a malicious link.Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Wordpress