CVE-2024-11277
The 404 Solution plugin through version 2.35.19 contains a reflected cross-site scripting vulnerability caused by inadequate sanitization of URL parameters and lack of proper output encoding. Attackers who are not authenticated can inject malicious scripts into web pages that will execute when users interact with specially crafted links. This vulnerability affects all versions prior to 2.35.20 and requires social engineering to successfully exploit, as the attacker must convince a user to click a malicious link.
Based on public CVE data (MITRE/NVD).