GHSA-fxpc-qmrh-7j2h

Suggest an improvement
Source
https://github.com/advisories/GHSA-fxpc-qmrh-7j2h
Import Source
https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2025/05/GHSA-fxpc-qmrh-7j2h/GHSA-fxpc-qmrh-7j2h.json
JSON Data
https://api.osv.dev/v1/vulns/GHSA-fxpc-qmrh-7j2h
Aliases
  • CVE-2024-11718
Published
2025-05-15T21:31:28Z
Modified
2025-05-20T18:57:11.179890Z
Severity
  • 4.8 (Medium) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N CVSS Calculator
Summary
tarteaucitron-wp WordPress Plugin Vulnerable to Stored Cross-Site Scripting
Details

The tarteaucitron-wp WordPress plugin before 0.3.0 allows author level and above users to add HTML into a post/page, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks.

Database specific
{
    "github_reviewed_at": "2025-05-20T17:55:38Z",
    "github_reviewed": true,
    "severity": "MODERATE",
    "nvd_published_at": "2025-05-15T20:15:35Z",
    "cwe_ids": [
        "CWE-79"
    ]
}
References

Affected packages

Packagist / couleurcitron/tarteaucitron-wp

Package

Name
couleurcitron/tarteaucitron-wp
Purl
pkg:composer/couleurcitron/tarteaucitron-wp

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
0.3.0

Affected versions

0.*
0.1.0
0.1.1
0.1.2
v0.*
v0.1.3
v0.1.4
v0.1.5
v0.2.0
v0.2.1
v0.2.2
v0.2.3
v0.2.4
v0.2.5

Database specific

source
"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2025/05/GHSA-fxpc-qmrh-7j2h/GHSA-fxpc-qmrh-7j2h.json"