Reflected Cross-Site Scripting Vulnerability in Simple:Press Forum Plugin for WordPress
CVE-2024-12409
6.1MEDIUM
What is CVE-2024-12409?
The Simple:Press Forum plugin for WordPress is susceptible to Reflected Cross-Site Scripting due to inadequate input sanitization of the 's' parameter. Unauthenticated attackers can exploit this vulnerability by crafting a malicious link. When a targeted user clicks such a link, they may inadvertently execute harmful scripts within their browser, compromising their session and potentially leading to data theft or other malicious actions.
Affected Version(s)
Simple:Press Forum 0 <= 6.10.11