CVE-2024-3978

CVE-2024-3978: WordPress Jitsi Shortcode <= 0.1 - Contributor+ Stored XSS via Shortcode

Vendor Unknown
Product WordPress Jitsi Shortcode
Published June 14, 2024
Last update August 1, 2024

CVSS base score

—

What the vulnerability does

01Description

The WordPress Jitsi Shortcode WordPress plugin through 0.1 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks

Key dates

02Disclosure timeline

June 14, 2024 CVE published
August 1, 2024 Record updated