CVE-2024-12682: Smart Maintenance Mode < 1.5.2 - Admin+ Stored XSS
The Smart Maintenance Mode WordPress plugin before 1.5.2 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfilteredhtml capability is disallowed (for example in multisite setup).
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-12682?
CVE-2024-12682 is considered a high severity vulnerability due to its potential for Stored Cross-Site Scripting attacks.
How do I fix CVE-2024-12682?
To fix CVE-2024-12682, update the Smart Maintenance Mode WordPress plugin to version 1.5.2 or later.
Who is affected by CVE-2024-12682?
CVE-2024-12682 affects users of the Smart Maintenance Mode WordPress plugin versions before 1.5.2.
What types of attacks are possible with CVE-2024-12682?
CVE-2024-12682 allows high privilege users like administrators to conduct Stored Cross-Site Scripting attacks.
Does CVE-2024-12682 affect sites with unfiltered_html capability disabled?
Yes, CVE-2024-12682 can still be exploited even if the unfiltered_html capability is disabled.