First published: Fri Jul 12 2024(Updated: )
The Simple Video Directory WordPress plugin before 1.4.4 does not sanitise and escape some of its settings, which could allow contributors and higher to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)
Credit: contact@wpscan.com
Affected Software | Affected Version | How to fix |
---|---|---|
Quantumcloud Simple Video Directory | <1.4.4 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2024-5811 is classified as a high severity vulnerability due to its potential for facilitating Stored Cross-Site Scripting attacks.
To remediate CVE-2024-5811, update the Simple Video Directory WordPress plugin to version 1.4.4 or later.
CVE-2024-5811 affects users of the Simple Video Directory WordPress plugin versions prior to 1.4.4.
CVE-2024-5811 is a Stored Cross-Site Scripting vulnerability that can be exploited by contributors and higher roles.
CVE-2024-5811 is particularly a concern in multisite WordPress setups where unfiltered_html capability is restricted.