CVE-2024-13112: WP MediaTagger <= 4.1.1 - Reflected XSS
Published Jan 31, 2025
·Updated
The WP MediaTagger WordPress plugin through 4.1.1 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin.
Affected Software
2 affected components
WP MediaTagger<=4.1.1
Phd38 Wp Mediatagger Wordpress<=4.1.1
Event History
Jan 31, 2025
CVE Published
via MITRE·06:00 AM
Data Sourced
via MITRE·06:00 AM
DescriptionWeakness
Frequently Asked Questions
1
What is the severity of CVE-2024-13112?
CVE-2024-13112 is classified as a critical vulnerability due to its potential for exploitation against high privilege users.
2
How do I fix CVE-2024-13112?
To fix CVE-2024-13112, update the WP MediaTagger plugin to the latest version above 4.1.1.
3
Who is affected by CVE-2024-13112?
CVE-2024-13112 affects users of the WP MediaTagger WordPress plugin version 4.1.1 and earlier.
4
What type of vulnerability is CVE-2024-13112?
CVE-2024-13112 is a reflected cross-site scripting (XSS) vulnerability.
5
Can CVE-2024-13112 be exploited remotely?
Yes, CVE-2024-13112 can be exploited remotely, targeting high privilege users such as administrators.