The wp-eMember WordPress plugin before 10.3.9 does not sanitize and escape the "fieldId" parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting.
Loading...
Loading...
Score 8.3 from GitHub Security Advisory (severity: HIGH) published 2024-06-04. NVD baseline CVSS 8.3; sources differ by 0.0.
The wp-eMember WordPress plugin before 10.3.9 does not sanitize and escape the "fieldId" parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting.
June 4, 2024
June 17, 2025
Explore the affected products and dependency analysis for CVE-2024-4749
EchelonGraph automatically scans your cloud infrastructure and maps CVE exposure using blast radius analysis.