S4E just found a high-severity finding from top 10 tcp port service scan
PlatformPlansPartners
Resources
ToolsBlogDocs
Sign Up →
medium·Product Based Web Vulnerabilities·Updated Feb 11, 2026

CVE-2024-13570 Scanner

CVE-2024-13570 Scanner - Cross-Site Scripting (XSS) vulnerability in WordPress Stray Random Quotes

Est. Time~10 seconds
Scan TypeSingle Scan
Targetsdomain, subdomain, ipv4
CostFree
2.8k
Times Used
continuous scan runs
5.9k
Continuously Checked
assets under CS
0
Vulnerabilities Found
confirmed findings
References
CVECVE-2024-13570
6.1
CVSSmedium
Exploitable remotely over the internet · no authentication required · user interaction needed.

The Stray Random Quotes WordPress plugin through 1.9.9 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin.

Attack Vector
Network
Privileges Req.
None
User Interaction
Required
Affected
Stray Random Quotes
0
Updated Sep 10, 2026View on NVD →
Detail

The WordPress Stray Random Quotes plugin is widely used to display random quotes on WordPress websites. It is particularly popular among blog and content creators looking to enhance user engagement with their sites. The plugin is maintained by Unaligned Code and is available through the WordPress plugin repository. This plugin allows users to manage and display quotes on their WordPress site with ease, offering flexibility in customization. It is typically used by site administrators who have the necessary permissions to install plugins on their sites. The plugin's simplicity and effectiveness make it a top choice for WordPress users worldwide looking to enhance content diversity.

The Cross-Site Scripting (XSS) vulnerability allows an attacker to inject malicious scripts into web pages viewed by other users. This vulnerability arises because the Stray Random Quotes plugin does not properly sanitize and escape user inputs. The exploitation of this vulnerability can occur when a high-privilege user clicks on a crafted malicious URL. Once exploited, this vulnerability allows the attacker to execute scripts in the context of the affected site, potentially leading to data theft or account compromise. The vulnerability is critical as it affects the confidentiality and integrity of the data.

Vulnerability details highlight the technical aspects of the XSS issue in the plugin, focusing on how a lack of input sanitization is the primary cause. The vulnerable endpoint involves a specific parameter that is susceptible to injection in the plugin's administration panel. Attackers can exploit this by crafting URLs that, when accessed by privileged users, execute arbitrary scripts. These scripts can perform actions on behalf of the user or steal session tokens. The combination of reflected XSS and high-privilege context makes this vulnerability particularly severe.

When exploited, this vulnerability can seriously affect more than just the immediate user targeted by the XSS attack. It can lead to the compromise of user accounts with high privileges, allowing attackers to take extensive control over the site's operations and data. This might include modifications to site content, installation of further malicious tools, or exfiltration of sensitive user data. Additionally, the website could potentially be leveraged to launch attacks against other online users or networks linked to the victims. The impact notably includes potential reputational damage and loss of user trust.

REFERENCES

Solution Advice
  • Update the Stray Random Quotes plugin to the latest version where this vulnerability is rectified.
  • Implement proper input validation and sanitization across all web inputs within the plugin to prevent malicious scripts injection.
  • Regularly audit and monitor the WordPress plugins installed on the site to ensure they are up to date and securely configured.
  • Consider using a web application firewall to help filter and monitor HTTP requests to the website, which can mitigate XSS attacks.
  • Encourage users, especially those with high-level permissions, to be cautious about clicking on unfamiliar or potentially suspicious URLs.

Get AI-powered remediation steps tailored to your asset.

Try AI Solutions →

Check your infrastructure.
Right now.

11,000+ scanners. Free to start. No credit card required.

CVE-2024-13570 Scanner - Cross-Site Scripting (XSS) vulnerability in WordPress Stray Random Quotes | S4E