The tarteaucitron-wp WordPress plugin before 0.3.0 allows author level and above users to add HTML into a post/page, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks.
CVE ID: CVE-2024-11718
Vendor: Unknown
Product: tarteaucitron-wp
EPSS Score: 0.03% (probability of being exploited)
EPSS Percentile: 6.04% (scored less or equal to compared to others)
EPSS Date: 2025-06-06 (when was this score calculated)