First published: Mon Apr 15 2024(Updated: )
The Responsive Tabs WordPress plugin before 4.0.7 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks
Credit: contact@wpscan.com
Affected Software | Affected Version | How to fix |
---|---|---|
I Thirteen Web Solution WP Responsive Tabs | <4.0.7 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2024-1846 has a high severity rating due to the potential for stored Cross-Site Scripting vulnerabilities.
To mitigate CVE-2024-1846, update the Responsive Tabs WordPress plugin to version 4.0.7 or later.
Users with the contributor role and above on WordPress sites using the affected version of the Responsive Tabs plugin are at risk.
CVE-2024-1846 can allow attackers to execute stored Cross-Site Scripting attacks, potentially leading to data theft or site compromise.
CVE-2024-1846 was disclosed in early 2024, highlighting the importance of keeping WordPress plugins updated.