CVE-2024-11183(rumspeed / simple_side_tab)

LOWCVSS 4.8 · MEDIUM

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

The Simple Side Tab WordPress plugin before 2.2.0 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-79

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

NONE

Momentum

NONE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • simple_side_tab

Threat summary

  • 1 mentions across 1 observed day

What's happening

  • 1 total mentions across 1 day

Affected systems

Vendors
Products
simple_side_tab

Deep dive

Activity timeline1 mentions / 1d
00111Mentions · 2026-10-02: 110-02
Full discourse1 post
  • JTCrawford@JtCrawford

    FortiMail zero-day (CVE-2024-11183) exploited in the wild — pre-auth RCE via SMTP. Attackers are hitting unpatched servers right now. Patches delayed for some versions. If you're running FortiMail, segment it yesterday. #infosec #zerodayexploit

    0000024
    82 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Apprumspeedsimple_side_tab-wordpress-

Explore more