CVE-2024-13569: Front End Users <= 3.2.32 - Reflected XSS
The Front End Users WordPress plugin through 3.2.32 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-13569?
CVE-2024-13569 has a high severity rating due to its potential for reflected cross-site scripting attacks affecting high privilege users.
How do I fix CVE-2024-13569?
To fix CVE-2024-13569, update the Front End Users WordPress plugin to a version above 3.2.32 where the vulnerability is patched.
Who is affected by CVE-2024-13569?
CVE-2024-13569 affects users of the Front End Users plugin for WordPress up to version 3.2.32, particularly high privilege users like admins.
What type of vulnerability is CVE-2024-13569?
CVE-2024-13569 is a reflected cross-site scripting (XSS) vulnerability that allows attackers to inject malicious scripts.
Can CVE-2024-13569 be exploited remotely?
Yes, CVE-2024-13569 can be exploited remotely by attackers to execute scripts in the context of the victim's browser.