WordPress plugin vulnerable to Stored Cross-Site Scripting
CVE-2024-11904
6.4MEDIUM
What is CVE-2024-11904?
The vulnerable WordPress plugin allows for stored cross-site scripting due to inadequate input sanitation and output escaping on the 'msntt_add_plus_talk' shortcode. This flaw affects all versions up to and including 1.2.0, enabling attackers with contributor-level access or higher to inject malicious scripts into web pages. These scripts are executed when a user accesses the compromised page, posing significant risks to user data and application integrity.
Affected Version(s)
코드엠샵 소셜톡 * <= 1.2.0