Reflected Cross-Site Scripting Vulnerability in SEMA API Plugin for WordPress
CVE-2024-12285
What is CVE-2024-12285?
The SEMA API plugin for WordPress contains a vulnerability that permits unauthenticated users to execute reflected cross-site scripting attacks. This is achieved through the 'catid' parameter, which lacks adequate input sanitization and output escaping. If attackers can manipulate users into clicking on a specific link, they can inject arbitrary web scripts that are then executed in the context of the user's session. This vulnerability underscores the importance of securing web applications through proper input handling techniques to maintain user trust and data integrity.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
SEMA API * <= 5.27
References
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved