CVE-2024-12808: WP ERP | Complete HR solution with recruitment < 1.13.4 - Admin+ Stored XSS
The WP ERP | Complete HR solution with recruitment & job listings | WooCommerce CRM & Accounting WordPress plugin before 1.13.4 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfilteredhtml capability is disallowed (for example in multisite setup).
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-12808?
CVE-2024-12808 is considered a high severity vulnerability due to its potential for Stored Cross-Site Scripting attacks.
How do I fix CVE-2024-12808?
To fix CVE-2024-12808, update the WP ERP plugin to version 1.13.4 or later.
Who is affected by CVE-2024-12808?
CVE-2024-12808 affects users of the WP ERP plugin for WordPress prior to version 1.13.4.
What type of vulnerability is CVE-2024-12808?
CVE-2024-12808 is categorized as a Stored Cross-Site Scripting (XSS) vulnerability.
Can low privilege users exploit CVE-2024-12808?
No, CVE-2024-12808 requires high privilege users, such as administrators, to exploit the vulnerability.