cleantalk
Vulnerabilities and Security Researches

AHAthat Plugin, CVE-2024-12595

CVE, Research URL

CVE-2024-12595

Application

AHAthat Plugin

Published on
Jan 02, 2025
Research Description
The AHAthat Plugin WordPress plugin through 1.6 does not escape the $_SERVER['REQUEST_URI'] parameter before outputting it back in an attribute, which could lead to Reflected Cross-Site Scripting in old web browsers
Affected versions
Min -, max 1.6.
Status
vulnerable