Reflected Cross-Site Scripting Vulnerability in VR-Frases WordPress Plugin
CVE-2024-13626
Key Information:
- Vendor
- WordPress
- Vendor
- CVE Published:
- 17 February 2025
Badges
Summary
The VR-Frases plugin for WordPress, up to version 3.0.1, is susceptible to a reflected cross-site scripting attack due to insufficient sanitization and escaping of user-supplied parameters. This vulnerability could allow attackers to execute scripts in the context of high-privilege users, such as administrators, potentially leading to unauthorized actions or data exposure directly through the affected web application. Proper input validation and escaping mechanisms are critical for securing user interactions.
Affected Version(s)
VR-Frases (collect & share quotes) 0 <= 3.0.1
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.
References
CVSS V3.1
Timeline
- 🟡
Public PoC available
- 👾
Exploit known to exist
Vulnerability published
Vulnerability Reserved