Stored Cross-Site Scripting in Skyword API Plugin for WordPress
CVE-2024-11907
6.4MEDIUM
What is CVE-2024-11907?
The Skyword API Plugin for WordPress is affected by a Stored Cross-Site Scripting vulnerability that arises from inadequate input sanitization and output escaping mechanisms. This flaw allows authenticated users, with contributor-level roles or higher, to inject malicious web scripts via the plugin's 'skyword_iframe' shortcode. The injected scripts are executed when users access the impacted pages, potentially leading to unauthorized actions or data exposure.
Affected Version(s)
Skyword API Plugin * <= 2.5.2