CVE-2024-9292
The Bridge Core plugin for WordPress contains a security flaw that allows malicious users with elevated access levels to embed potentially hazardous code snippets into website content, which can then be executed by visitors when accessing the compromised pages. This vulnerability arises from inadequate filtering of user-provided data and insufficient protection against script injection in the 'formforall' shortcode functionality. The issue affects plugin versions up to 3.2.0.
Based on public CVE data (MITRE/NVD).