Vulnerability Description
The Bulk Me Now! WordPress plugin through 2.0 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Ombu | Bulk Me Now\! | <= 2.0 |
Related Weaknesses (CWE)
References
- https://wpscan.com/vulnerability/8f30a37e-b9d0-467b-a0e3-20dc0a9f2b61/ExploitThird Party Advisory
- https://wpscan.com/vulnerability/8f30a37e-b9d0-467b-a0e3-20dc0a9f2b61/ExploitThird Party Advisory
FAQ
What is CVE-2024-12708?
CVE-2024-12708 is a vulnerability with a CVSS score of 7.1 (HIGH). The Bulk Me Now! WordPress plugin through 2.0 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow u...
How severe is CVE-2024-12708?
CVE-2024-12708 has been rated HIGH with a CVSS base score of 7.1/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2024-12708?
Check the references section above for vendor advisories and patch information. Affected products include: Ombu Bulk Me Now\!.