CVE-2024-11382
Common Ninja: Fully Customizable & Perfectly Responsive Free Widgets for WordPress Websites <= 1.1.0 - Authenticated (Contributor+) Stored Cross-Site Scripting
The Common Ninja: Fully Customizable & Perfectly Responsive Free Widgets for WordPress Websites plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'commonninja' shortcode in all versions up to, and including, 1.1.0 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
| CWE | CWE-79 |
| Vendor | commonninja |
| Product | common ninja: fully customizable & perfectly responsive free widgets for wordpress websites |
| Published | Jan 7, 2025 |
| Last Updated | Apr 8, 2026 |
Get instant alerts for commonninja common ninja: fully customizable & perfectly responsive free widgets for wordpress websites
Be the first to know when new medium vulnerabilities affecting commonninja common ninja: fully customizable & perfectly responsive free widgets for wordpress websites are published โ delivered to Slack, Telegram or Discord.
CVSS v3 Breakdown
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N