/Vulnerability Library

WP Extended < 3.0.0 - Stored Cross-Site Scripting

CVE-2024-37259
Verified

Description

The Ultimate WordPress Toolkit - WP Extended plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 2.4.7 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

Severity

Medium

CVSS Score

6.1

Exploit Probability

1%

Affected Product

wp-extended

Published Date

January 5, 2026

Template Author

0xanis

CVE-2024-37259.yaml
6.1Score

CVSS Metrics

CVSS Vector:
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
CVE ID:
cve-2024-37259
CWE ID:
cwe-79

References

https://wpscan.com/vulnerability/2d90ca7d-e957-4ac6-b1f1-2d631bffa2e8/https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/wpextended/the-ultimate-wordpress-toolkit-wp-extended-247-unauthenticated-stored-cross-site-scriptinghttps://plugins.trac.wordpress.org/changeset/3099195/wpextendedhttps://nvd.nist.gov/vuln/detail/CVE-2024-37259

Remediation Steps

Update to WP Extended 3.0.0 or later.