CVE Database /
CVE-2024-10176
CVE · Medium
CVE-2024-10176 — Compact WP Audio Player [compact-wp-audio-player] < 1.9.14
| CVE |
Vulnerability |
Type |
Severity |
Affected |
Fixed in |
Published |
Status |
|
CVE-2024-10176
|
Compact WP Audio Player [compact-wp-audio-player] < 1.9.14 |
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') |
Medium
6.4
|
< 1.9.14
|
1.9.14 |
2024-10-23 |
—
|
CVE-2024-10176
The Compact WP Audio Player plugin contains a stored cross-site scripting vulnerability in its sc_embed_player shortcode affecting versions 1.9.13 and earlier. Authenticated users with contributor privileges or higher can inject malicious scripts through inadequately sanitized shortcode attributes, and these scripts will run when anyone views the affected pages. The vulnerability stems from a failure to properly validate inputs and escape outputs. Version 1.9.14 addresses this security issue.
Based on public CVE data (MITRE/NVD).
Scan your WordPress site free
No signup, no credit card — enter your URL and get a security report in seconds.
See the full security page for this plugin
Browse the CVE database
Browse all security findings