CVE-2024-3919

CVE-2024-3919: OpenPGP Form Encryption for WordPress < 1.5.1 - Contributor+ Stored XSS

Vendor Unknown
Product OpenPGP Form Encryption for WordPress
Published July 13, 2024
Last update August 1, 2024

CVSS base score

—

What the vulnerability does

01Description

The OpenPGP Form Encryption for WordPress plugin before 1.5.1 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks.

Key dates

02Disclosure timeline

July 13, 2024 CVE published
August 1, 2024 Record updated