CVE-2024-13347
The Essential WP Real Estate WordPress plugin through 1.1.3 does not escape generated URLs before outputting them in att
The Essential WP Real Estate WordPress plugin through 1.1.3 does not escape generated URLs before outputting them in attributes, leading to Reflected Cross-Site Scripting.
MEDIUM · CVSS 6.8
EPSS 0.00108
Schedule remediation
- Public exploit or PoC is available
Sigma rules0
YARA rules0