← Database

CVE-2024-3773

MEDIUM CVSS: 5.9 Published: 2026-09-02 Modified: 2026-09-02

Description

The LiveJournal Shortcode WordPress plugin through 1.1.1 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks

Affected Platforms

Unknown

Weakness Type

CWE-79

References