CVE · Medium

CVE-2024-10176 — Compact WP Audio Player [compact-wp-audio-player] < 1.9.14

CVE Vulnerability Type Severity Affected Fixed in Published Status
CVE-2024-10176 Compact WP Audio Player [compact-wp-audio-player] < 1.9.14 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Medium 6.4 < 1.9.14 1.9.14 2024-10-23

CVE-2024-10176

The Compact WP Audio Player plugin contains a stored cross-site scripting vulnerability in its sc_embed_player shortcode affecting versions 1.9.13 and earlier. Authenticated users with contributor privileges or higher can inject malicious scripts through inadequately sanitized shortcode attributes, and these scripts will run when anyone views the affected pages. The vulnerability stems from a failure to properly validate inputs and escape outputs. Version 1.9.14 addresses this security issue.

Based on public CVE data (MITRE/NVD).

Scan your WordPress site free

No signup, no credit card — enter your URL and get a security report in seconds.