CVE-2024-13492: Guten Free Options <= 0.9.5 - Reflected XSS
The Guten Free Options WordPress plugin through 0.9.5 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-13492?
CVE-2024-13492 is classified as a medium severity vulnerability due to its potential impact on high privilege users.
How do I fix CVE-2024-13492?
To fix CVE-2024-13492, update the Guten Free Options WordPress plugin to version 0.9.6 or later where the vulnerability has been addressed.
Who is affected by CVE-2024-13492?
CVE-2024-13492 affects users of the Guten Free Options plugin version 0.9.5 and earlier.
What kind of attack can be executed using CVE-2024-13492?
CVE-2024-13492 allows for a Reflected Cross-Site Scripting (XSS) attack which could compromise high privilege accounts such as administrators.
Is there a workaround for CVE-2024-13492?
As a temporary workaround for CVE-2024-13492, administrators can restrict access to the affected functionality or disable the plugin until it is updated.