First published: Thu Jan 09 2025(Updated: )
The Aklamator INfeed WordPress plugin through 2.0.0 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).
Credit: contact@wpscan.com
Affected Software | Affected Version | How to fix |
---|---|---|
Aklamator INfeed | <=2.0.0 | |
WordPress | <=2.0.0 | |
Aklamator INfeed WordPress | <=2.0.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2024-12717 has a medium severity rating due to its potential for Stored Cross-Site Scripting attacks.
To fix CVE-2024-12717, update the Aklamator INfeed plugin to version 2.0.1 or later, which addresses the vulnerability.
CVE-2024-12717 affects users of the Aklamator INfeed WordPress plugin up to version 2.0.0.
The risks of CVE-2024-12717 include potential exploitation by high privilege users to execute malicious scripts within the WordPress environment.
Yes, CVE-2024-12717 can specifically affect multisite WordPress installations where unfiltered_html capabilities are disallowed.