SEPTEMBER 17, 2026
Live Feed
Back to database
Case File

CVE-2024-3773

MEDIUM · CVSS 5.9 EPSS 0.14%

Source: NVD + CISA KEV + EPSS · Published 2026-09-02 · Last synced 2026-09-17

CyberRota Analysis

AI-Generated

The LiveJournal Shortcode plugin for WordPress versions up to 1.1.1 is vulnerable due to inadequate validation and escaping of shortcode attributes, potentially allowing users with contributor roles and higher to execute Stored Cross-Site Scripting (XSS) attacks. This vulnerability could lead to unauthorized script execution on affected sites, compromising user data and site integrity. WordPress site administrators, especially those using this plugin, should prioritize updating to mitigate the risk of exploitation.

CVE
CVE-2024-3773
Severity
MEDIUM
CVSS
5.9
EPSS
0.14%
WordPress

Original NVD Description

The LiveJournal Shortcode WordPress plugin through 1.1.1 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks