CVE-2024-9182 in the Maspik – Advanced Spam Protection plugin allows an attacker to embed saved cross-site scripts (XSS). This vulnerability can lead to serious consequences, such as creating an administrator account without authorization, which can compromise the security of WordPress websites.
CVE-2024-9182 – Maspik – Advanced Spam Protection – Stored XSS to Admin Creation – POC
