CVE-2024-13721CWE-85

Plethora Plugins Tabs + Accordions <= 1.1.8 - Authenticated (Contributor+) Stored Cross-Site Scripting via anchor

Medium · published January 25, 2025

CVSS v3.1
6.4
EPSS
0%
Percentile
18.9
In the wild
Unconfirmed
What it is

The Plethora Plugins Tabs + Accordions plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the anchor parameter in all versions up to, and including, 1.1.8 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

The record
Technical detail
CVSS v3.1
6.4 · MEDIUM
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N
CVSS v4.0
Not supplied
EPSS
0.00270 · 18.9th percentile
Weakness
CWE-85 · Doubled Character XSS Manipulations
Published
2025-01-25T05:30Z
EPSS history
Timeline
  • 25 JAN 05:30Z
    Plethora Plugins Tabs + Accordions <= 1.1.8 - Authenticated (Contributor+) Stored Cross-Site Scripting via anchor
    cvelistv5