CVE-2024-12722

The Twitter Bootstrap Collapse aka Accordian Shortcode WordPress plugin through 1.0 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks.
Configurations

Configuration 1 (hide)

cpe:2.3:a:mohsinrasool:twitter_bootstrap_collapse_aka_accordian_shortcode:*:*:*:*:*:wordpress:*:*

History

11 Jun 2025, 17:23

Type Values Removed Values Added
CPE cpe:2.3:a:mohsinrasool:twitter_bootstrap_collapse_aka_accordian_shortcode:*:*:*:*:*:wordpress:*:*
References () https://wpscan.com/vulnerability/c3be5990-ca89-4ac4-baae-49af55df9d57/ - () https://wpscan.com/vulnerability/c3be5990-ca89-4ac4-baae-49af55df9d57/ - Exploit, Third Party Advisory
CWE CWE-79
First Time Mohsinrasool
Mohsinrasool twitter Bootstrap Collapse Aka Accordian Shortcode

20 May 2025, 20:15

Type Values Removed Values Added
References () https://wpscan.com/vulnerability/c3be5990-ca89-4ac4-baae-49af55df9d57/ - () https://wpscan.com/vulnerability/c3be5990-ca89-4ac4-baae-49af55df9d57/ -
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 5.4

16 May 2025, 14:43

Type Values Removed Values Added
Summary
  • (es) El complemento Twitter Bootstrap Collapse aka Accordian Shortcode para WordPress en su versión 1.0, no valida ni escapa algunos de los atributos de su shortcode antes de mostrarlos nuevamente en una página o publicación donde está incrustado el shortcode, lo que podría permitir a los usuarios con rol de colaborador o superior realizar ataques de Cross-Site Scripting.

15 May 2025, 20:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-05-15 20:15

Updated : 2025-06-11 17:23


NVD link : CVE-2024-12722

Mitre link : CVE-2024-12722

CVE.ORG link : CVE-2024-12722


JSON object : View

Products Affected

mohsinrasool

  • twitter_bootstrap_collapse_aka_accordian_shortcode
CWE
CWE-79

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')