In WP Finance plugin for WordPress versions 1.3.6 and prior a high severity vulnerability CVE-2024-13097 was detected. This vulnerability allows attackers to execute malicious scripts via a Reflected Cross-Site Scripting (XSS) attack, potentially targeting high-privilege users such as admins. Currently, there is no fix version for this issue. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2024-13097.
WordPress: Reflected Cross-Site Scripting Vulnerability in WP Finance plugin
by the Hossted team
03.02.2025