CVE-2024-13419 is a Stored Cross-Site Scripting (XSS) vulnerability affecting multiple WordPress plugins and themes utilizing the Smart Framework, including g5plus april, auteur, benaa, and beyot. The vulnerability stems from a missing capability check in the saveOptions() and importThemeOptions() functions, allowing authenticated attackers with Subscriber-level access or higher to inject malicious JavaScript into site-wide settings. Rated Medium severity (CVSS 5.4), this flaw requires user interaction (UI:R) but can lead to client-side compromise (C:L, I:L). There is currently no evidence of active exploitation, public exploit code, or significant community discussion, and it is not listed on the KEV catalog.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 5.1CPE matchmatch criteria | cpe:2.3:a:g5plus:april:*:*:*:*:*:wordpress:*:* | ||
<= 7.1CPE matchmatch criteria | cpe:2.3:a:g5plus:auteur:*:*:*:*:*:wordpress:*:* | ||
<= 4.0.0CPE matchmatch criteria | cpe:2.3:a:g5plus:benaa:*:*:*:*:*:wordpress:*:* | ||
<= 6.0.6CPE matchmatch criteria | cpe:2.3:a:g5plus:beyot:*:*:*:*:*:wordpress:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.