CVE-2024-11199
Published
CVSS v3
6.4
MEDIUM
CVSS v2
N/A
Affected
1
PROJECT
Description
The Rescue Shortcodes plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's rescue_progressbar shortcode in all versions up to, and including, 2.9 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
<p>When activated, this plugin will add a button to the WordPress text editor to easily insert shortcodes to your posts or pages.</p>
<p><strong>Included shortcodes:</strong></p>
<ul>
<li>Button – With many options including unlimited colors and Icons.</li>
<li>Content Toggle – Maybe for an awesome FAQ page.</li>
<li>Tabbed Content – Create tabbed sections for your content.</li>
<li><a href="http://fortawesome.github.io/Font-Awesome/" rel="nofollow ugc">Font Awesome</a> Icons – 500+ icons and counting.</li>
<li>Animations – Wrap anything with the animation shortcode and watch it come alive.</li>
<li>Notification Box – Have certain sections of text stand out by creating notices or alerts.</li>
<li>Text Highlight – Quickly highlight sections of text to help more important words stand out.</li>
<li>Columns – Separate your content with multiple column options.</li>
<li>Spacing – Add space between sections on the fly.</li>
<li>Progress Bar – Display a sliding progress notification bar</li>
</ul>
<h3>License Info</h3>
<p>Font Awesome – http://fontawesome.io<br />
Fonts: SIL OFL 1.1, CSS: MIT License – http://fontawesome.io/license<br />
Copyright: @davegandy</p>
<p>Wow.js – https://github.com/matthieua/WOW<br />
MIT License – https://github.com/matthieua/WOW/blob/master/LICENSE-MIT<br />
Copyright: @mattaussaguel</p>
<p>animate.css – https://github.com/daneden/animate.css<br />
MIT License – https://github.com/daneden/animate.css#license<br />
Copyright: @_dte</p>
<p>Waypoints – https://github.com/imakewebthings/waypoints<br />
MIT License – https://github.com/imakewebthings/waypoints/blob/master/licenses.txt<br />
Copyright: @foodgoesinmouth</p>