1 results (0.001 seconds)
CVSS: 7.1EPSS: 0%CPEs: 1EXPL: 1

CVE-2024-13885 – WP E Customers <= 0.0.1 - Reflected XSS
https://notcve.org/view.php?id=CVE-2024-13885
20 Feb 2025 — The WP e-Customers Beta WordPress plugin through 0.0.1 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin. The WP e-Customers Beta plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in all versions up to, and including, 0.0.1 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary... • https://wpscan.com/vulnerability/b64d17d6-8416-476e-ad78-b7b9cb85b84f • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •