CVE-2024-5627

CVE-2024-5627: WordPress Plugin Tournamatch < 4.6.1 - Subscriber+ Stored XSS

Vendor Unknown
Product Tournamatch
Published July 13, 2024
Last update March 27, 2025

CVSS base score

—

What the vulnerability does

01Description

The Tournamatch WordPress plugin before 4.6.1 does not sanitise and escape some parameters, which could allow users with a role as low as subscriber to perform Cross-Site Scripting attacks.

Key dates

02Disclosure timeline

July 13, 2024 CVE published
March 27, 2025 Record updated