CVE-2024-3918
Pet Manager <= 1.4 - Contributor+ Stored XSS
The Pet Manager WordPress plugin through 1.4 does not sanitise and escape some of its Pet settings, which could allow high privilege users such as Contributor to perform Stored Cross-Site Scripting attacks.
CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N
Affected products
Unknown · Pet ManagerWant to know if your infrastructure is exposed to this?
Talk to TrueHacking →