CVE-2024-5811: Simple Video Directory < 1.4.4 - Contributor+ Stored XSS
The Simple Video Directory WordPress plugin before 1.4.4 does not sanitise and escape some of its settings, which could allow contributors and higher to perform Stored Cross-Site Scripting attacks even when the unfilteredhtml capability is disallowed (for example in multisite setup)
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-5811?
CVE-2024-5811 is classified as a high severity vulnerability due to its potential for facilitating Stored Cross-Site Scripting attacks.
How do I fix CVE-2024-5811?
To remediate CVE-2024-5811, update the Simple Video Directory WordPress plugin to version 1.4.4 or later.
Who is affected by CVE-2024-5811?
CVE-2024-5811 affects users of the Simple Video Directory WordPress plugin versions prior to 1.4.4.
What type of vulnerability is CVE-2024-5811?
CVE-2024-5811 is a Stored Cross-Site Scripting vulnerability that can be exploited by contributors and higher roles.
In what environment is CVE-2024-5811 a concern?
CVE-2024-5811 is particularly a concern in multisite WordPress setups where unfiltered_html capability is restricted.