Legull WordPress - Cross-Site Scripting
CVE-2024-13352
Verified
Description
Legull WordPress plugin <= 1.2.2 contains a reflected cross-site scripting caused by unsanitized parameter output, letting attackers execute arbitrary scripts in the context of high privilege users, exploit requires victim to click malicious link.
Severity
High
CVSS Score
7.1
Exploit Probability
1%
Published Date
February 6, 2026
Template Author
sourabh-sahu
CVE-2024-13352.yaml
7.1Score
CVSS Metrics
CVSS Vector:
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L
CVE ID:
cve-2024-13352
CWE ID:
cwe-79
Remediation Steps
Update to the latest version of the plugin where the vulnerability is fixed.