/Vulnerability Library

Legull WordPress - Cross-Site Scripting

CVE-2024-13352
Verified

Description

Legull WordPress plugin <= 1.2.2 contains a reflected cross-site scripting caused by unsanitized parameter output, letting attackers execute arbitrary scripts in the context of high privilege users, exploit requires victim to click malicious link.

Severity

High

CVSS Score

7.1

Exploit Probability

1%

Published Date

February 6, 2026

Template Author

sourabh-sahu

CVE-2024-13352.yaml
7.1Score

CVSS Metrics

CVSS Vector:
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L
CVE ID:
cve-2024-13352
CWE ID:
cwe-79

References

https://wpscan.com/vulnerability/2c141cc0-f79e-42bd-97a6-98829647104c/https://nvd.nist.gov/vuln/detail/CVE-2024-13352

Remediation Steps

Update to the latest version of the plugin where the vulnerability is fixed.