Stray Random Quotes WordPress plugin <= 1.9.9 contains a reflected cross-site scripting caused by a lack of sanitization and escaping of a parameter before output, letting attackers execute malicious scripts in the context of high privilege users, exploit requires attacker to craft a malicious URL.
id: CVE-2024-13570
info:
name: WordPress Stray Random Quotes <= 1.9.9 - Cross-Site Scripting
au
...