CVE · Medium

CVE-2024-9292 — Bridge Core [bridge-core] < 3.3

CVE Vulnerability Type Severity Affected Fixed in Published Status
CVE-2024-9292 Bridge Core [bridge-core] < 3.3 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Medium 6.4 < 3.3 3.3 2024-10-07

CVE-2024-9292

The Bridge Core plugin for WordPress contains a security flaw that allows malicious users with elevated access levels to embed potentially hazardous code snippets into website content, which can then be executed by visitors when accessing the compromised pages. This vulnerability arises from inadequate filtering of user-provided data and insufficient protection against script injection in the 'formforall' shortcode functionality. The issue affects plugin versions up to 3.2.0.

Based on public CVE data (MITRE/NVD).

Scan your WordPress site free

No signup, no credit card — enter your URL and get a security report in seconds.