The Giveaways and Contests by RafflePress WordPress plugin before 1.12.17 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).
Metrics
Affected Vendors & Products
References
History
Wed, 04 Jun 2025 21:00:00 +0000
Type | Values Removed | Values Added |
---|---|---|
First Time appeared |
Seedprod
Seedprod rafflepress |
|
Weaknesses | CWE-79 | |
CPEs | cpe:2.3:a:seedprod:rafflepress:*:*:*:*:*:wordpress:*:* | |
Vendors & Products |
Seedprod
Seedprod rafflepress |
Tue, 20 May 2025 16:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Metrics |
cvssV3_1
|
Thu, 15 May 2025 20:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | The Giveaways and Contests by RafflePress WordPress plugin before 1.12.17 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup). | |
Title | Giveaways and Contests by RafflePress < 1.12.17 - Admin+ Stored XSS | |
References |
|

Status: PUBLISHED
Assigner: WPScan
Published: 2025-05-15T20:06:41.208Z
Updated: 2025-05-20T15:56:49.030Z
Reserved: 2024-10-17T19:00:13.635Z
Link: CVE-2024-10107

Updated: 2025-05-20T15:56:43.876Z

Status : Analyzed
Published: 2025-05-15T20:15:32.707
Modified: 2025-06-04T20:38:31.237
Link: CVE-2024-10107

No data.