CVE Database /
CVE-2024-1768
CVE · Medium
CVE-2024-1768 — Clever Fox [clever-fox] < 25.2.1
| CVE |
Vulnerability |
Type |
Severity |
Affected |
Fixed in |
Published |
Status |
|
CVE-2024-1768
|
Clever Fox [clever-fox] < 25.2.1 |
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') |
Medium
5.4
|
< 25.2.1
|
25.2.1 |
2024-06-06 |
—
|
CVE-2024-1768
The Clever Fox plugin for WordPress contains a stored cross-site scripting vulnerability in its info box block affecting versions up to 25.2.0. Authenticated users with contributor or higher permissions can inject malicious scripts through unsanitized user-supplied attributes on the block because the plugin fails to properly escape output. When visitors access pages containing the injected script, the malicious code executes in their browsers.
Based on public CVE data (MITRE/NVD).
Scan your WordPress site free
No signup, no credit card — enter your URL and get a security report in seconds.
See the full security page for this plugin
Browse the CVE database
Browse all security findings