Vulnerability
Stored Cross Site Scripting (XSS) in chatWindow functionality in WordPress Clicksold IDX Plugin <= 1.90
Description
The plugin does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).
CVE-ID
CVE-2024-7769
Vendor
WordPress
Product
Clicksold IDX Plugin
Disclosure Timeline
Made Public On: 24-09-2024
Reported On 09-07-2024
Fixed On: Not Fixed
Credits
Amandeep Singh Banga