Stored Cross-Site Scripting in Point Maker Plugin for WordPress
CVE-2024-12815
6.4MEDIUM
What is CVE-2024-12815?
The Point Maker plugin for WordPress allows authenticated users with contributor-level access and above to exploit a vulnerability in its 'point_maker' shortcode. Due to inadequate input sanitization and output escaping of user-supplied attributes, attackers can inject arbitrary web scripts that execute when other users access affected pages. This poses a significant risk as it can lead to unauthorized actions and compromise user data.
Affected Version(s)
Point Maker * <= 0.1.6