Stored Cross-Site Scripting Flaw in Slotti Ajanvaraus WordPress Plugin
CVE-2024-11408
6.4MEDIUM
What is CVE-2024-11408?
The Slotti Ajanvaraus plugin for WordPress contains a Stored Cross-Site Scripting vulnerability that arises from inadequate input sanitization and output escaping. This issue is triggered through the plugin's 'slotti' shortcode, impacting all versions up to and including 1.3.0. Authenticated attackers with contributor-level access can exploit this vulnerability to inject arbitrary web scripts into pages. The injected scripts can execute whenever a user accesses the compromised page, leading to potential security risks such as data theft, session hijacking, and defacement of web content.
Affected Version(s)
Slotti Ajanvaraus 0 <= 1.3.0