First published: Tue Jul 30 2024(Updated: )
The Responsive Tabs WordPress plugin through 4.0.8 does not sanitise and escape some of its Tab settings, which could allow high privilege users such as Contributors and above to perform Stored Cross-Site Scripting attacks
Credit: contact@wpscan.com
Affected Software | Affected Version | How to fix |
---|---|---|
I Thirteen Web Solution WP Responsive Tabs | <4.0.8 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2024-4096 has a high severity due to the potential for stored Cross-Site Scripting attacks by high privilege users.
To fix CVE-2024-4096, update the Responsive Tabs WordPress plugin to version 4.0.9 or later.
CVE-2024-4096 affects users of the Responsive Tabs plugin for WordPress versions up to and including 4.0.8.
CVE-2024-4096 can enable Stored Cross-Site Scripting attacks, allowing attackers to inject malicious scripts.
CVE-2024-4096 can compromise WordPress site security by allowing unauthorized users to execute harmful scripts if not patched.