Stored Cross-Site Scripting in Utilities for MTG Plugin by WordPress
CVE-2024-13433
6.4MEDIUM
What is CVE-2024-13433?
The Utilities for MTG plugin for WordPress contains a vulnerability that allows authenticated attackers with contributor-level access or higher to exploit Stored Cross-Site Scripting via the plugin's 'mtglink' shortcode. This issue arises from inadequate input sanitization and output escaping on user-supplied attributes, enabling the injection of arbitrary web scripts. As a result, these scripts will execute when users access the affected pages, potentially compromising the integrity of the site.
Affected Version(s)
Utilities for MTG * <= 1.4.1