6.4
CVSSv3

CVE-2024-13433

CVSSv4: NA | CVSSv3: 6.4 | CVSSv2: NA | VMScore: 740 | EPSS: 0.00102 | KEV: Not Included
Published: 18/01/2025 Updated: 18/01/2025

Vulnerability Summary

Stored Cross-Site Scripting Vulnerability in WordPress MTG Plugin 1.4.1

The Utilities for MTG plugin for WordPress has a Stored Cross-Site Scripting vulnerability. This happens through the plugin's 'mtglink' shortcode in versions up to 1.4.1. The issue is due to poor input sanitization and output escaping on user-supplied attributes. Authenticated attackers with contributor access or higher can inject harmful web scripts. These scripts run when a user visits a page with the injected code.

Vulnerable Product Search on Vulmon Subscribe to Product

yunra utilities for mtg