Vulnerability Description
The WP-Recall WordPress plugin before 16.26.12 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).
CVSS Score
LOW
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Plechevandrey | Wp-Recall | < 16.26.12 |
Related Weaknesses (CWE)
References
- https://wpscan.com/vulnerability/c33adc08-99c5-42e1-a2e3-e7c3412a6a3f/ExploitThird Party Advisory
FAQ
What is CVE-2024-9771?
CVE-2024-9771 is a vulnerability with a CVSS score of 3.5 (LOW). The WP-Recall WordPress plugin before 16.26.12 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks e...
How severe is CVE-2024-9771?
CVE-2024-9771 has been rated LOW with a CVSS base score of 3.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2024-9771?
Check the references section above for vendor advisories and patch information. Affected products include: Plechevandrey Wp-Recall.