S4E just found a high-severity finding from top 10 tcp port service scan
PlatformPlansPartners
Resources
ToolsBlogDocs
Sign Up →
medium·Product Based Web Vulnerabilities·Updated Feb 9, 2026

CVE-2024-12724 Scanner

CVE-2024-12724 Scanner - Cross-Site Scripting (XSS) vulnerability in WP DeskLite

Est. Time~10 seconds
Scan TypeSingle Scan
Targetsdomain, subdomain, ipv4
CostFree
3.4k
Times Used
continuous scan runs
5.8k
Continuously Checked
assets under CS
0
Vulnerabilities Found
confirmed findings
References
CVECVE-2024-12724
6.1
CVSSmedium
Exploitable remotely over the internet · no authentication required · user interaction needed.

The WP DeskLite WordPress plugin through 1.0.0 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin.

Attack Vector
Network
Privileges Req.
None
User Interaction
Required
Affected
WP DeskLite
0
Updated Aug 22, 2026View on NVD →
Detail

WP DeskLite is a WordPress plugin widely utilized by administrators and developers to manage and customize their WordPress sites. Developed by Codeflock, it enhances website functionality and user interaction through a variety of tools and widgets. This plugin is primarily employed to streamline the management of help desk operations within WordPress environments. The diverse functionalities it offers make it a valuable asset for businesses and individuals aiming to optimize their digital presence. WP DeskLite's user-friendly interface allows both experienced developers and novice users to implement changes with ease. However, like many plugins, it requires regular updates and patches to safeguard against vulnerabilities.

The vulnerability detected in WP DeskLite is a Reflected Cross-Site Scripting (XSS) flaw. This type of vulnerability allows attackers to inject malicious scripts into web applications, which are then reflected back to users. Specifically, this vulnerability exists due to unsanitized and unescaped parameter output within the plugin. Attacks leveraging this vulnerability typically require the victim to click on a crafted link, allowing the execution of scripts in high-privilege users' browsers, such as administrators. This can potentially facilitate unauthorized actions and compromise sensitive user data. The impact of this vulnerability underscores the critical importance of input validation and output sanitization in web applications.

The technical details reveal that the plugin's endpoint '/wp-admin/edit.php?post_type=wpdl_ticket' is vulnerable. The vulnerability is characterized by the improper handling of certain parameters, allowing attackers to execute JavaScript via crafted input. By embedding a payload such as `">

Solution Advice
  • Update WP DeskLite to the latest version that includes patches for input sanitization and output escaping.
  • Implement a web application firewall (WAF) to detect and block malicious requests targeting known parameters.
  • Regularly review and audit plugins for potential vulnerabilities and apply security best practices.
  • Restrict access to administrative interfaces and enforce the principle of least privilege.
  • Educate users about the risks of clicking on untrusted links and monitor for suspicious activity.

Get AI-powered remediation steps tailored to your asset.

Try AI Solutions →

Check your infrastructure.
Right now.

11,000+ scanners. Free to start. No credit card required.