CVE-2024-5627

CVE-2024-5627: WordPress Plugin Tournamatch < 4.6.1 - Subscriber+ Stored XSS

Vendor Unknown
Product Tournamatch
Published July 13, 2024
Last update March 27, 2025

CVSS base score

What the vulnerability does

01Description

The Tournamatch WordPress plugin before 4.6.1 does not sanitise and escape some parameters, which could allow users with a role as low as subscriber to perform Cross-Site Scripting attacks.

Key dates

02Disclosure timeline

July 13, 2024 CVE published
March 27, 2025 Record updated