In Competition Form plugin for WordPress versions 2.0 and prior a medium severity vulnerability CVE-2024-12749 was detected. This vulnerability allows attackers to execute reflected cross-site scripting (XSS) attacks, which could target high-privilege users such as administrators. Currently, there is no fix version for this issue. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2024-12749.
WordPress: Reflected XSS Vulnerability in Competition Form Plugin
by the Hossted team
29.01.2025