Stored Cross-Site Scripting Vulnerability in SweepWidget Plugin for WordPress
CVE-2024-11756
6.4MEDIUM
Key Information:
- Vendor
Wordpress
- Vendor
- CVE Published:
- 7 January 2025
What is CVE-2024-11756?
The SweepWidget plugin for WordPress is affected by a stored cross-site scripting vulnerability due to inadequate input sanitization and output escaping on user-supplied data within the 'sweepwidget' shortcode. This vulnerability affects all versions up to and including 2.0.6, allowing authenticated users with contributor-level access and above to inject malicious scripts. These scripts execute whenever a user loads a compromised page, posing a significant risk to both the website’s integrity and its users’ data.
Affected Version(s)
SweepWidget Contests, Giveaways, Photo Contests, Competitions * <= 2.0.6