CVE-2024-13621: The GDPR Framework By Data443 < 2.2.0 - Admin+ Stored XSS
The GDPR Framework By Data443 WordPress plugin before 2.2.0 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfilteredhtml capability is disallowed (for example in multisite setup).
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-13621?
CVE-2024-13621 is considered a high severity vulnerability due to its potential for Stored Cross-Site Scripting attacks.
How do I fix CVE-2024-13621?
To fix CVE-2024-13621, update the Data443 GDPR Framework WordPress plugin to version 2.2.0 or later.
Who is affected by CVE-2024-13621?
CVE-2024-13621 affects WordPress sites using the Data443 GDPR Framework plugin versions prior to 2.2.0.
What type of vulnerability is CVE-2024-13621?
CVE-2024-13621 is a Stored Cross-Site Scripting vulnerability.
Can users without admin privileges exploit CVE-2024-13621?
No, CVE-2024-13621 can only be exploited by high privilege users such as admins.