CVE-2024-13727 Information

Description

The MemberSpace WordPress plugin before 2.1.14 does not sanitise and escape a parameter before outputting it back in the page leading to a Reflected Cross-Site Scripting which could be used against only unauthenticated users.

Reference

https://wpscan.com/vulnerability/598d20f2-0f42-48f2-a941-0d6c5da5303e/

Share on: