CVE-2024-12734

The Advance Post Prefix WordPress plugin through 1.1.1, Advance Post Prefix WordPress plugin through 1.1.1 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin.
Configurations

Configuration 1 (hide)

cpe:2.3:a:niceit:advance_post_prefix:*:*:*:*:*:wordpress:*:*

History

22 May 2025, 19:11

Type Values Removed Values Added
CWE CWE-79
First Time Niceit advance Post Prefix
Niceit
CPE cpe:2.3:a:niceit:advance_post_prefix:*:*:*:*:*:wordpress:*:*
References () https://wpscan.com/vulnerability/038b44dc-0495-4f56-ae7e-c78a265aa535/ - () https://wpscan.com/vulnerability/038b44dc-0495-4f56-ae7e-c78a265aa535/ - Exploit, Third Party Advisory

20 May 2025, 20:15

Type Values Removed Values Added
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 6.1
References () https://wpscan.com/vulnerability/038b44dc-0495-4f56-ae7e-c78a265aa535/ - () https://wpscan.com/vulnerability/038b44dc-0495-4f56-ae7e-c78a265aa535/ -

16 May 2025, 14:43

Type Values Removed Values Added
Summary
  • (es) El complemento Advance Post Prefix de WordPress hasta la versión 1.1.1, el complemento Advance Post Prefix de WordPress hasta la versión 1.1.1 no depura ni escapa un parámetro antes de mostrarlo nuevamente en la página, lo que genera un Cross-Site Scripting reflejado que podría usarse contra usuarios con privilegios altos, como el administrador.

15 May 2025, 20:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-05-15 20:15

Updated : 2025-05-22 19:11


NVD link : CVE-2024-12734

Mitre link : CVE-2024-12734

CVE.ORG link : CVE-2024-12734


JSON object : View

Products Affected

niceit

  • advance_post_prefix
CWE
CWE-79

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')