CVE-2024-13101: WP MediaTagger <= 4.1.1 - Contributor+ Stored XSS
The WP MediaTagger WordPress plugin through 4.1.1 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-13101?
CVE-2024-13101 is considered a medium severity vulnerability due to its potential for Stored Cross-Site Scripting attacks.
How do I fix CVE-2024-13101?
To fix CVE-2024-13101, update the WP MediaTagger plugin to version 4.1.2 or later.
Who is affected by CVE-2024-13101?
CVE-2024-13101 affects users of the WP MediaTagger WordPress plugin version 4.1.1 and below.
What type of attack can be executed due to CVE-2024-13101?
CVE-2024-13101 allows for Stored Cross-Site Scripting attacks by users with the contributor role and higher.
What components of the WP MediaTagger plugin are vulnerable in CVE-2024-13101?
The vulnerability in CVE-2024-13101 exists due to improper validation and escaping of shortcode attributes in the WP MediaTagger plugin.