Stored Cross-Site Scripting Vulnerability in Quote Post Type Plugin by WordPress
CVE-2024-13386
What is CVE-2024-13386?
The Quote Post Type Plugin for WordPress has a vulnerability characterized by Stored Cross-Site Scripting. This occurs through the Author field due to inadequate sanitization of user inputs and failure to properly escape outputs. Authenticated attackers with Contributor-level access or higher can exploit this flaw by injecting malicious web scripts into pages, leading to potential execution of these scripts whenever a user accesses the compromised page. All versions of the plugin up to and including 1.2.2 are affected.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
quote-posttype-plugin * <= 1.2.2
References
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved