CVE-2024-10639: Auto Prune Posts < 3.0.0- Admin+ Stored XSS
The Auto Prune Posts WordPress plugin before 3.0.0 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfilteredhtml capability is disallowed (for example in multisite setup).
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-10639?
CVE-2024-10639 has a high severity rating due to its potential to allow Stored Cross-Site Scripting attacks by attackers with high privileges.
How do I fix CVE-2024-10639?
To fix CVE-2024-10639, update the Auto Prune Posts WordPress plugin to version 3.0.0 or later.
Who is affected by CVE-2024-10639?
CVE-2024-10639 affects installations of the Auto Prune Posts WordPress plugin prior to version 3.0.0.
What type of vulnerability is CVE-2024-10639?
CVE-2024-10639 is a Stored Cross-Site Scripting vulnerability that arises from improper sanitization of plugin settings.
Can CVE-2024-10639 affect multisite installations?
Yes, CVE-2024-10639 can affect multisite installations where high privilege users have access to the Auto Prune Posts plugin.