Stored Cross-Site Scripting Vulnerability in Easy Waveform Player for WordPress
CVE-2024-11881
Summary
The Easy Waveform Player plugin for WordPress is susceptible to a Stored Cross-Site Scripting (XSS) vulnerability through its 'easywaveformplayer' shortcode. This security flaw, present in all versions up to and including 1.2.0, arises from the plugin's failure to properly sanitize and escape user-supplied input. As a result, authenticated attackers with contributor-level access and higher can exploit this weakness to inject arbitrary web scripts into pages. When a user accesses such an affected page, the injected scripts execute, potentially leading to unauthorized actions or data breaches. Website administrators are strongly advised to update the plugin to the latest version and implement robust security measures to mitigate these risks.
References
CVSS V3.1
Timeline
Vulnerability published