CVE-2024-13347: XSS
The Essential WP Real Estate WordPress plugin through 1.1.3 does not escape generated URLs before outputting them in attributes, leading to Reflected Cross-Site Scripting.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-13347?
The severity of CVE-2024-13347 is categorized as moderate due to its potential for Reflected Cross-Site Scripting attacks.
How do I fix CVE-2024-13347?
To fix CVE-2024-13347, update the Essential WP Real Estate plugin to version 1.1.4 or later, where the URL escaping issue is resolved.
Which versions of the Essential WP Real Estate plugin are affected by CVE-2024-13347?
CVE-2024-13347 affects all versions of the Essential WP Real Estate plugin up to and including version 1.1.3.
What type of attack can exploit CVE-2024-13347?
CVE-2024-13347 can be exploited through Reflected Cross-Site Scripting attacks due to improperly escaped URLs.
Is CVE-2024-13347 considered a serious security risk?
While CVE-2024-13347 is not classified as high severity, it still poses a security risk that could lead to malicious script execution.