VYPR
Moderate severityNVD Advisory· Published May 15, 2025· Updated May 20, 2025

tarteaucitron.js for WordPress < 0.3.0 - Author+ Stored XSS

CVE-2024-11718

Description

The tarteaucitron-wp WordPress plugin before 0.3.0 allows author level and above users to add HTML into a post/page, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected packages

Versions sourced from the GitHub Security Advisory.

PackageAffected versionsPatched versions
couleurcitron/tarteaucitron-wpPackagist
< 0.3.00.3.0

Affected products

2

Patches

Vulnerability mechanics

References

4

News mentions

0

No linked articles in our index yet.