Loading HuntDB...

GHSA-gq4f-rq24-q85j

GitHub Security Advisory

⚠ Unreviewed MODERATE Has CVE

Advisory Details

Multiple plugins for WordPress are vulnerable to Reflected Cross-Site Scripting via the cminds_free_guide shortcode in various versions due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a link.

Related CVEs

Key Information

GHSA ID
GHSA-gq4f-rq24-q85j
Published
November 26, 2024 9:30 AM
Last Modified
November 26, 2024 9:30 AM
CVSS Score
5.0 /10
Primary Ecosystem
Unknown
Primary Package
Unknown
GitHub Reviewed
✗ No

Dataset

Last updated: July 12, 2025 6:29 AM

Data from GitHub Advisory Database. This information is provided for research and educational purposes.