CVE-2024-12717: aklamator-infeed <= 2.0.0 - Admin+ Stored XSS
The Aklamator INfeed WordPress plugin through 2.0.0 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfilteredhtml capability is disallowed (for example in multisite setup).
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-12717?
CVE-2024-12717 has a medium severity rating due to its potential for Stored Cross-Site Scripting attacks.
How do I fix CVE-2024-12717?
To fix CVE-2024-12717, update the Aklamator INfeed plugin to version 2.0.1 or later, which addresses the vulnerability.
Who is affected by CVE-2024-12717?
CVE-2024-12717 affects users of the Aklamator INfeed WordPress plugin up to version 2.0.0.
What are the risks associated with CVE-2024-12717?
The risks of CVE-2024-12717 include potential exploitation by high privilege users to execute malicious scripts within the WordPress environment.
Can CVE-2024-12717 affect multisite WordPress installations?
Yes, CVE-2024-12717 can specifically affect multisite WordPress installations where unfiltered_html capabilities are disallowed.