CVE-2024-11357 Information

Description

The goodlayers-core WordPress plugin before 2.0.10 does not sanitise and escape some of its settings which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks.

Reference

https://wpscan.com/vulnerability/7e8c6816-9b7a-43e8-9508-789c8051dd9b/

Share on: