{ "id": "CVE-2024-2444", "sourceIdentifier": "contact@wpscan.com", "published": "2024-04-06T05:15:07.500", "lastModified": "2024-04-08T18:49:25.863", "vulnStatus": "Awaiting Analysis", "cveTags": [], "descriptions": [ { "lang": "en", "value": "The Inline Related Posts WordPress plugin before 3.5.0 does not sanitise and escape some of its settings, which could allow high privilege users such as Admin to perform Cross-Site Scripting attacks even when unfiltered_html is disallowed" }, { "lang": "es", "value": "El complemento Related Posts de WordPress en l\u00ednea anterior a 3.5.0 no desinfecta ni escapa a algunas de sus configuraciones, lo que podr\u00eda permitir a usuarios con altos privilegios, como el administrador, realizar ataques de cross-site scripting incluso cuando unfiltered_html no est\u00e1 permitido." } ], "metrics": {}, "references": [ { "url": "https://wpscan.com/vulnerability/214e5fd7-8684-418a-b67d-60b1dcf11a48/", "source": "contact@wpscan.com" } ] }