CVE-2024-13357: Ditty – Responsive News Tickers, Sliders, and Lists < 3.1.52 - Author+ Stored XSS
The Ditty WordPress plugin before 3.1.52 does not sanitise and escape some of its settings, which could allow high privilege users such as author to perform Stored Cross-Site Scripting attacks even when the unfilteredhtml capability is disallowed (for example in multisite setup).
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-13357?
CVE-2024-13357 is considered a high severity vulnerability due to its potential for Stored Cross-Site Scripting attacks by high privilege users.
How do I fix CVE-2024-13357?
To fix CVE-2024-13357, you should update the Ditty WordPress plugin to version 3.1.52 or later.
Who is affected by CVE-2024-13357?
CVE-2024-13357 affects users of the Ditty WordPress plugin versions before 3.1.52, particularly in multisite setups.
What type of vulnerability is CVE-2024-13357?
CVE-2024-13357 is a Stored Cross-Site Scripting vulnerability due to inadequate sanitization and escaping in plugin settings.
Can low privilege users exploit CVE-2024-13357?
No, only high privilege users, such as authors, can exploit CVE-2024-13357 to perform attacks.