CVE · Medium

CVE-2024-1768 — Clever Fox [clever-fox] < 25.2.1

CVE Vulnerability Type Severity Affected Fixed in Published Status
CVE-2024-1768 Clever Fox [clever-fox] < 25.2.1 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Medium 5.4 < 25.2.1 25.2.1 2024-06-06

CVE-2024-1768

The Clever Fox plugin for WordPress contains a stored cross-site scripting vulnerability in its info box block affecting versions up to 25.2.0. Authenticated users with contributor or higher permissions can inject malicious scripts through unsanitized user-supplied attributes on the block because the plugin fails to properly escape output. When visitors access pages containing the injected script, the malicious code executes in their browsers.

Based on public CVE data (MITRE/NVD).

Scan your WordPress site free

No signup, no credit card — enter your URL and get a security report in seconds.