CVE-2024-13119: XSS
The Paid Membership Plugin, Ecommerce, User Registration Form, Login Form, User Profile & Restrict Content WordPress plugin before 4.15.20 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfilteredhtml capability is disallowed (for example in multisite setup).
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-13119?
CVE-2024-13119 has a high severity rating due to its potential to allow stored cross-site scripting attacks.
How do I fix CVE-2024-13119?
To fix CVE-2024-13119, update the Paid Membership Plugin to version 4.15.20 or later.
Who is affected by CVE-2024-13119?
CVE-2024-13119 affects users of the Paid Membership Plugin for WordPress versions before 4.15.20.
What types of attacks can CVE-2024-13119 lead to?
CVE-2024-13119 can lead to stored cross-site scripting attacks that affect high privilege users such as admins.
What settings are vulnerable in CVE-2024-13119?
CVE-2024-13119 involves the settings of the Paid Membership Plugin that are not properly sanitized and escaped.