Record summary

CVE-2024-13727 has a selected CVSS score of 6.1 (medium); EIP currently links 1 Nuclei template.

Description

The MemberSpace WordPress plugin before 2.1.14 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against only unauthenticated users.

Description source: CVE List

Exploitation context

Available material

Nuclei templates
1

CISA SSVC decision

ExploitationPoC
AutomatableNo
Technical impactPartial

CISA Coordinator · SSVC 2.0.3 · Evaluated May 20, 2025 · Source: CVE List

Affected products and versions

1
ProductSourceVersion rangeStatus

MemberSpace

Default status: unaffected

CVE ListBefore 2.1.14affected

Nuclei templates

1
ProjectDiscoveryMEDIUMMemberSpace WordPress - Cross-Site ScriptingCVSS 6.1

MemberSpace WordPress plugin < 2.1.14 contains a reflected XSS caused by unsanitized and unescaped parameter output, letting unauthenticated attackers execute scripts, exploit requires no authentication.

Impact

Unauthenticated attackers can execute scripts in users' browsers, potentially stealing data or performing actions on their behalf.

Remediation

Upgrade to version 2.1.14 or later.

WeaknessesCWE-79
AuthorsSourabh-Sahu
Template tagscvecve2024memberspaceunauthxsswordpresswpwp-plugin
CVSS vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
CPE: cpe:2.3:a:memberspace:memberspace:*:*:*:*:*:wordpress:*:*

Source: ProjectDiscovery

References

2