cleantalk
Vulnerabilities and Security Researches

Inline Related Posts, CVE-2024-5626

CVE, Research URL

CVE-2024-5626

Application

Inline Related Posts

Published on
Jul 12, 2024
Research Description
The Inline Related Posts WordPress plugin before 3.7.0 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin
Affected versions
max 3.7.0.
Status
vulnerable