
CVE-2024-11190 - Stored XSS in Jwp-a11y WordPress plugin through 4.1.7. High privilege users can inject scripts even with unfiltered_html disabled. CVSS 0? No patch available. Review and restrict plugin use immediately. #CVE #WordPress #CVEAlerts
Post summary
The post identifies a stored XSS flaw in the Jwp-a11y WordPress plugin (CVE‑2024‑11190) with no patch available, urging immediate restriction of the plugin to mitigate risk.
