CVE-2024-11718: tarteaucitron.js for WordPress < 0.3.0 - Author+ Stored XSS

Description

The tarteaucitron-wp WordPress plugin before 0.3.0 allows author level and above users to add HTML into a post/page, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks.

Classification

CVE ID: CVE-2024-11718

Problem Types

CWE-79 Cross-Site Scripting (XSS)

Affected Products

Vendor: Unknown

Product: tarteaucitron-wp

Exploit Prediction Scoring System (EPSS)

EPSS Score: 0.03% (probability of being exploited)

EPSS Percentile: 6.04% (scored less or equal to compared to others)

EPSS Date: 2025-06-06 (when was this score calculated)

References

https://nvd.nist.gov/vuln/detail/CVE-2024-11718
https://wpscan.com/vulnerability/02da3a49-20e4-4476-a78d-4c627994a90a/

Timeline