CVE-2024-13602: Poll Maker < 5.5.4 - Admin+ Stored XSS
The Poll Maker WordPress plugin before 5.5.4 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfilteredhtml capability is disallowed (for example in multisite setup).
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-13602?
The severity of CVE-2024-13602 is considered high due to the potential for Stored Cross-Site Scripting attacks.
How do I fix CVE-2024-13602?
To fix CVE-2024-13602, update the Poll Maker WordPress plugin to version 5.5.4 or later.
Who is affected by CVE-2024-13602?
CVE-2024-13602 affects WordPress installations using the Poll Maker plugin version prior to 5.5.4.
What kind of attack can CVE-2024-13602 lead to?
CVE-2024-13602 can lead to Stored Cross-Site Scripting attacks by allowing high privilege users to inject malicious scripts.
Is user permission relevant to the risk of CVE-2024-13602?
Yes, even with restricted unfiltered_html capability, high privilege users such as admins can exploit CVE-2024-13602.