CVE-2024-4753: WP Secure Maintenance < 1.7 - Admin+ Stored XSS
The WP Secure Maintenance WordPress plugin before 1.7 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfilteredhtml capability is disallowed (for example in multisite setup)
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-4753?
CVE-2024-4753 is classified as a high severity vulnerability due to its potential for stored Cross-Site Scripting attacks.
How do I fix CVE-2024-4753?
To fix CVE-2024-4753, upgrade the WP Secure Maintenance WordPress plugin to version 1.7 or later.
Who is affected by CVE-2024-4753?
CVE-2024-4753 affects users of the WP Secure Maintenance plugin prior to version 1.7, particularly those with high privilege roles.
What types of attacks are possible with CVE-2024-4753?
CVE-2024-4753 allows high privilege users to perform stored Cross-Site Scripting attacks.
Does CVE-2024-4753 affect all WordPress installations?
CVE-2024-4753 specifically affects installations using WP Secure Maintenance plugin versions prior to 1.7.