CVE Database
/

CVE-2024-13362

Back to search

CVE-2024-13362

Published: May 1, 2026

Modified: May 1, 2026

PUBLISHED

CVSS v3.1

6.1

MEDIUM

Description

Multiple plugins and/or themes for WordPress are vulnerable to Reflected Cross-Site Scripting via the url parameter in various versions due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a link.

VendorProductVersions

sebet

Go Fetch Jobs (for WP Job Manager)

affected
0 - <= 1.8.4.8.1

5starplugins

Dynamic Copyright Year

affected
0 - <= 1.0.4

peterschulznl

Code Manager

affected
0 - <= 1.0.40

bplugins

Advanced Scrollbar – Custom Scrollbar Styling and Behavior

affected
0 - <= 1.1.3

yuvalo

Goal Tracker – Custom Event Tracking for GA4

affected
0 - <= 1.1.5

essekia

Tablesome Table – Contact Form DB – WPForms, CF7, Gravity, Forminator, Fluent

affected
0 - <= 1.1.13

josevega

WP Page Templates

affected
0 - <= 1.1.16

hkdigitalagency

Payment Gateway for ACBA BANK

affected
0 - <= 1.2.6

princeahmed

Dracula Dark Mode – Accessibility, Reading Mode & Dark Mode for WordPress

affected
0 - <= 1.2.7

spiderdevs

Forumax – AI Powered Advanced Community Forum Plugin

affected
0 - <= 1.2.7

seezee

Five-Star Ratings Shortcode

affected
0 - <= 1.2.56

oxilab

Product Layouts for WooCommerce

affected
0 - <= 1.3.1

mr2p

Meta Field Block – Display custom fields in the Block Editor without coding

affected
0 - <= 1.3.3

themelocation

Custom WooCommerce Checkout Fields Editor

affected
0 - <= 1.3.4

100plugins

Open User Map

affected
0 - <= 1.4.0

wpdever

WP Notification Bell

affected
0 - <= 1.4.2

themelocation

Remove Add to Cart WooCommerce

affected
0 - <= 1.4.7

princeahmed

File Manager for Google Drive – Integrate Google Drive

affected
0 - <= 1.4.9

5starplugins

Marijuana Age Verify

affected
0 - <= 1.5.5

infosatech

RevivePress – Keep your Old Content Evergreen

affected
0 - <= 1.5.8

nicheaddons

Restaurant & Cafe Addon for Elementor

affected
0 - <= 1.5.8

paretodigital

Send Users Email – Email Subscribers, Email Marketing Newsletter

affected
0 - <= 1.5.10

unitecms

Unlimited Elements For Elementor

affected
0 - <= 1.5.140

meowcrew

Role Based Pricing for Woo by Meow Crew

affected
0 - <= 1.6.0

nicheaddons

Primary Addon for Elementor

affected
0 - <= 1.6.0

5starplugins

Featured Images in RSS for Mailchimp & More

affected
0 - <= 1.6.3

wpsaad

Image Alt Text Manager – Bulk & Dynamic Alt Tags For image SEO Optimization + AI

affected
0 - <= 1.6.3

kofimokome

Message Filter for Contact Form 7

affected
0 - <= 1.6.3.2

paretodigital

Embedder for Google Reviews

affected
0 - <= 1.6.6

interactivegeomaps

MapGeo – Interactive Geo Maps

affected
0 - <= 1.6.22

wpbits

WPBITS Addons For Elementor Page Builder

affected
0 - <= 1.7

toddhalfpenny

Widgets on Pages

affected
0 - <= 1.7

rebelcode

Spotlight Social Feeds – Block, Shortcode, and Widget

affected
0 - <= 1.7.0

tobias_conrad

WOW Styler for CF7 – Visual Styler for Contact Form 7 Forms

affected
0 - <= 1.7.0

webfactory

AI Bud – AI Content Generator, AI Chatbot, ChatGPT, Gemini, GPT-4o

affected
0 - <= 1.7.2

hasanazizul

Text To Speech TTS Accessibility

affected
0 - <= 1.7.34

5starplugins

Easy Age Verify

affected
0 - <= 1.8.5

senols

AI Puffer – Chat. Create. Automate. (formerly AI Power)

affected
0 - <= 1.8.99

damian-gora

Justified Gallery

affected
0 - <= 1.9.0

mapster

Mapster WP Maps

affected
0 - <= 1.9.0

streamweasels

StreamWeasels Twitch Integration

affected
0 - <= 1.9.2

xplodedthemes

XT Variation Swatches for WooCommerce

affected
0 - <= 1.9.4

bplugins

bBlocks – Essential Gutenberg Blocks & Patterns Collection

affected
0 - <= 1.9.8

kaizencoders

URL Shortify – Simple and Easy URL Shortener

affected
0 - <= 1.10.4

uriahs-victor

Kikote – Location Picker at Checkout & Google Address AutoFill Plugin for WooCommerce

affected
0 - <= 1.10.6

cyberhobo

Geo Mashup

affected
0 - <= 1.13.15

josevega

Disable Payment Methods based on cart conditions for WooCommerce

affected
0 - <= 1.16.3

pagup

Automatic Internal Links for SEO by Pagup

affected
0 - <= 2.0.0

enweby

Full Screen Background

affected
0 - <= 2.0.2

litonice13

Master Addons For Elementor – Widgets, Extensions, Theme Builder, Popup Builder & Template Kits

affected
0 - <= 2.0.7.2

princeahmed

Radio Player – Live Shoutcast, Icecast and Any Audio Stream Player

affected
0 - <= 2.0.82

spicethemes

Carousel, Recent Post Slider and Banner Slider

affected
0 - <= 2.1

pagup

Bulk Auto Image Alt Text (Alt tag, Alt attribute) optimizer (image SEO)

affected
0 - <= 2.1.0

xplodedthemes

XT Quick View for WooCommerce

affected
0 - <= 2.1.5

pluginscafe

Smart phone field for Gravity Forms

affected
0 - <= 2.1.6

fooplugins

Notification Bar, Announcement and Cookie Notice WordPress Plugin – FooBar

affected
0 - <= 2.1.34

bplugins

PDF Poster – Display PDF Files with Custom Viewer

affected
0 - <= 2.2.0

nicheaddons

Events Addon for Elementor

affected
0 - <= 2.2.2

bplugins

HTML5 Audio Player – The Ultimate No-Code Podcast, MP3 & Audio Player

affected
0 - <= 2.2.27

mte90

Glossary

affected
0 - <= 2.2.38

tickera

Restrict – membership, site, content and user access restrictions for WordPress

affected
0 - <= 2.3.0

cyclonecode

Custom PHP Settings

affected
0 - <= 2.3.1

prasadkirpekar

WP Meta and Date Remover

affected
0 - <= 2.3.4

fullworks

Anti-Spam Protection – No API Key, GDPR Friendly

affected
0 - <= 2.3.7

premmerce

Premmerce Permalink Manager for WooCommerce

affected
0 - <= 2.3.11

smartwpress

Music Player for Elementor – Audio Player & Podcast Player

affected
0 - <= 2.4.1

mhmrajib

TopNewsWp – Display Tikcer News, RSS Feed Widget and Many More

affected
0 - <= 2.4.1

oceanwp

Ocean Extra

affected
0 - <= 2.4.2

fooplugins

Gallery by FooGallery

affected
0 - <= 2.4.27

plugins360

Automatic YouTube Gallery

affected
0 - <= 2.5.5

spiderdevs

EazyDocs – AI Powered Knowledge Base, Wiki, Documentation & FAQ Builder

affected
0 - <= 2.5.7

samdani

Team Members – A WordPress Team Plugin with Gallery, Grid, Carousel, Slider, Table, List, and More

affected
0 - <= 2.5.8

tonyzeoli

Radio Station by netmix® – Manage and play your Show Schedule in WordPress!

affected
0 - <= 2.5.9

kaira

StoreCustomizer – A plugin to Customize all WooCommerce Pages

affected
0 - <= 2.5.9

wpjoli

Joli Table Of Contents

affected
0 - <= 2.6.0

passionatebrains

GA4WP – Analytics Dashboard for the Website

affected
0 - <= 2.6.0

nitin247

Place Order Without Payment for WooCommerce

affected
0 - <= 2.6.5

wordplus

Better Messages – Live Chat, Chat Rooms, Real-Time Messaging & Private Messages

affected
0 - <= 2.6.7

mihail-barinov

Share This Image

affected
0 - <= 2.07

inavii

Inavii Social Feed

affected
0 - <= 2.7.0

fooplugins

Lightbox & Modal Popup WordPress Plugin – FooBox

affected
0 - <= 2.7.33

xplodedthemes

XT Floating Cart for WooCommerce

affected
0 - <= 2.8.4

takanakui

WP Mobile Menu – The Mobile-Friendly Responsive Menu

affected
0 - <= 2.8.6

passionatebrains

AEH Speed Optimization: Browser Cache, Optimized Minify, Lazy Loading & Image Optimization

affected
0 - <= 2.9.2

bensibley

Independent Analytics

affected
0 - <= 2.9.7

codesavory

Knowledge Base documentation & wiki plugin – BasePress Docs

affected
0 - <= 2.16.3.3

davidanderson

Internal Link Juicer: SEO Auto Linker for WordPress

affected
0 - <= 2.24.6

josevega

Bulk Edit Posts and Products in Spreadsheet

affected
0 - <= 2.25.16

saadiqbal

Post SMTP – Complete Email Deliverability and SMTP Solution with Email Logs, Alerts, Backup SMTP & Mobile App

affected
0 - <= 3.0.0

tobiasbg

TablePress – Tables in WordPress made easy

affected
0 - <= 3.0.2

bouncingsprout

Ultimeter

affected
0 - <= 3.0.5

blackandwhitedigital

TreePress – Easy Family Trees & Ancestor Profiles

affected
0 - <= 3.0.6

mattpramschufer

Pay For Post with WooCommerce

affected
0 - <= 3.1.26

koen12344

Post to Google My Business (Google Business Profile)

affected
0 - <= 3.1.28

imtiazrayhan

WP Coupons and Deals – Coupon Plugin For Affiliate Marketers

affected
0 - <= 3.2.2

pluginsware

Advanced Classifieds & Directory Pro

affected
0 - <= 3.2.4

gallerycreator

Mixed Media Gallery Blocks

affected
0 - <= 3.2.4.4

blockspare

BlockSpare — News, Magazine and Blog Addons for (Gutenberg) Block Editor

affected
0 - <= 3.2.6

mhmrajib

AidWP – Donation & Payment Forms (Stripe Powered)

affected
0 - <= 3.2.6

infornweb

Logo Showcase – Responsive Logo Carousel, Logo Slider & Logo Grid

affected
0 - <= 3.2.7

pluginandplay

Post Slider and Post Carousel with Post Vertical Scrolling Widget – A Responsive Post Slider

affected
0 - <= 3.2.7

samdani

Solid Testimonials – Testimonial Slider, Video Testimonials & Customer Reviews

affected
0 - <= 3.2.8

wpspeedo

Team Members Showcase

affected
0 - <= 3.3.0

elespare

EleSpare – News, Magazine and Blog Addons for Elementor

affected
0 - <= 3.3.2

infornweb

Post List Designer – Category Post, Recent Post, Post List

affected
0 - <= 3.3.7

infornweb

Blog Designer Pack – Blog, Post Grid, Post Slider, Post Carousel, Category Post, News

affected
0 - <= 3.4.9

dashlabsltd

YASR – Yet Another Star Rating Plugin for WordPress

affected
0 - <= 3.4.12

xplodedthemes

WPIDE – File Manager & Code Editor

affected
0 - <= 3.5.1

premmerce

Premmerce Product Filter for WooCommerce

affected
0 - <= 3.7.3

afthemes

WP Post Author – Author Box, Multiple Authors, Guest Authors & Custom Avatars

affected
0 - <= 3.8.3

wpmagics

Delete Posts automatically

affected
0 - <= 3.9.6

takanakui

Menu Image, Icons made easy

affected
0 - <= 3.12

passionatebrains

AWCA – The Great Analytics Insights for Your eStore

affected
0 - <= 3.12.0

mikewire_rocksolid

Announcement & Notification Banner – Bulletin

affected
0 - <= 3.12.1

nitin247

Thank You Page for WooCommerce

affected
0 - <= 4.2.0

webheadllc

Contact Form 7 Multi-Step Forms

affected
0 - <= 4.4.1

speedify

Auto-Install Free SSL – Generate & Install Free SSL Certificates

affected
0 - <= 4.5.0

mhmrajib

WP Books Gallery – Build Stunning Book Showcases & Libraries in Minutes

affected
0 - <= 4.6.8

webba-agency

Easy Appointment Booking & Scheduling System – Webba Booking Calendar

affected
0 - <= 5.0.57

invisnet

WP fail2ban – Advanced Security

affected
0 - <= 5.3.4

vinod-dalvi

Ivory Search – WordPress Search Plugin

affected
0 - <= 5.5.8

peterschulznl

WP Data Access – App Builder for Tables, Forms, Charts, Maps & Dashboards

affected
0 - <= 5.5.31

elliotvs

Coupon Affiliates – Affiliate Plugin for WooCommerce

affected
0 - <= 5.17.2

cleverplugins

Security Ninja – WordPress Security & Firewall

affected
0 - <= 5.222

theafricanboss

Checkout with Cash App on WooCommerce

affected
0 - <= 6.0.2

fullworks

Display Eventbrite Events

affected
0 - <= 6.1.10

mohsinoffline

Secure Gateway for Authorize.net and WooCommerce by Pledged Plugins

affected
0 - <= 6.1.13

sjaved

Easy Social Feed – Social Photos Gallery and Post Feed for WordPress

affected
0 - <= 6.6.5

gn_themes

WP Shortcodes Plugin — Shortcodes Ultimate

affected
0 - <= 7.3.3

gowebsmarty

WP Encryption – One Click Free SSL Certificate & SSL / HTTPS Redirect, Security & SSL Scan

affected
0 - <= 7.7.0

tripetto

WordPress form builder plugin for contact forms, surveys and quizzes – Tripetto

affected
0 - <= 8.0.7

Weaknesses (CWE)

CVSS v3.1 Details

CVSS v3.1 Vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N

Attack Vector

Network

Attack Complexity

Low

Privileges Required

None

User Interaction

Required

Scope

Changed

Confidentiality

Low

Integrity

Low

Availability

None

References

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now