Medium severity5.4NVD Advisory· Published May 15, 2025· Updated Jun 17, 2026
CVE-2024-11718
CVE-2024-11718
Description
The tarteaucitron-wp WordPress plugin before 0.3.0 allows author level and above users to add HTML into a post/page, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
couleurcitron/tarteaucitron-wpPackagist | < 0.3.0 | 0.3.0 |
Affected products
3- cpe:2.3:a:couleurcitron:tarteaucitron-wp:*:*:*:*:*:wordpress:*:*Range: <0.3.0
- WordPress plugin/tarteaucitron-wp plugindescription
Patches
Vulnerability mechanics
References
4- wpscan.com/vulnerability/02da3a49-20e4-4476-a78d-4c627994a90a/nvdExploitThird Party Advisory
- github.com/advisories/GHSA-fxpc-qmrh-7j2hghsaADVISORY
- nvd.nist.gov/vuln/detail/CVE-2024-11718ghsaADVISORY
- wpscan.com/vulnerability/02da3a49-20e4-4476-a78d-4c627994a90aghsaWEB
News mentions
0No linked articles in our index yet.