CVE Database
/

CVE-2024-11202

Back to search

CVE-2024-11202

Published: Nov 26, 2024

Modified: Apr 8, 2026

PUBLISHED

CVSS v3.1

6.1

MEDIUM

Description

Multiple plugins for WordPress are vulnerable to Reflected Cross-Site Scripting via the cminds_free_guide shortcode in various versions due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a link.

VendorProductVersions

creativemindssolutions

CM Header and Footer – Add custom scripts and styles to your header and footer with ease

affected
0 - <= 1.2.1

creativemindssolutions

CM Business Directory – Optimise and showcase local business

affected
0 - <= 1.4.1

creativemindssolutions

CM Search And Replace – Optimize content edits with a powerful search and replace tool

affected
0 - <= 1.4.2

creativemindssolutions

CM E-Mail Blacklist – Simple email filtering for safer registration

affected
0 - <= 1.5.3

creativemindssolutions

CM Pop-Up – Create engaging popups to capture attention and boost interaction

affected
0 - <= 1.7.5

creativemindssolutions

CM Video Lessons Manager – Simplify video lessons management for better education

affected
0 - <= 1.8.2

creativemindssolutions

CM Tooltip Glossary

affected
0 - <= 4.3.11

Weaknesses (CWE)

CVSS v3.1 Details

CVSS v3.1 Vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N

Attack Vector

Network

Attack Complexity

Low

Privileges Required

None

User Interaction

Required

Scope

Changed

Confidentiality

Low

Integrity

Low

Availability

None

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now