S4E just found a high-severity finding from top 10 tcp port service scan
PlatformPlansPartners
Resources
ToolsBlogDocs
Sign Up →
medium·Product Based Web Vulnerabilities·Updated Feb 11, 2026

CVE-2024-13097 Scanner

CVE-2024-13097 Scanner - Cross-Site Scripting (XSS) vulnerability in WP Finance Plugin

Est. Time~10 seconds
Scan TypeSingle Scan
Targetsdomain, subdomain, ipv4
CostFree
3.1k
Times Used
continuous scan runs
3.9k
Continuously Checked
assets under CS
0
Vulnerabilities Found
confirmed findings
References
CVECVE-2024-13097
5.4
CVSSmedium
Exploitable remotely over the internet · low-privilege account sufficient.

The WP Finance WordPress plugin through 1.3.6 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin.

Attack Vector
Network
Privileges Req.
Low
User Interaction
None
Affected
WP Finance
0
Updated Aug 22, 2026View on NVD →
Detail

The WP Finance Plugin is widely used by small to medium-sized companies that require financial functionalities on their WordPress websites. This plugin is specifically designed for managing various financial tasks such as invoicing, expense tracking, and budgeting right from the WordPress dashboard. It is predominantly used by website administrators and financial staff who utilize WordPress for business operations. Given its integration with the WordPress CMS, it serves as an essential tool in extending financial capabilities to WordPress interfaces. Despite its usefulness, the plugin needs to be appropriately secured to prevent exploits like Cross-Site Scripting (XSS) and other vulnerabilities. Regular updates and patching are necessary to ensure it doesn't become a vector for attacks.

The Cross-Site Scripting (XSS) vulnerability in the WP Finance Plugin can enable attackers to execute scripts in the browsers of users with high privileges. This is particularly dangerous as XSS attacks can lead to unauthorized access to user sessions and lead to account compromises. The vulnerability arises from inadequate sanitization of a user-input parameter before output, which can be exploited when a user clicks on a malicious link crafted by an attacker. XSS vulnerabilities continue to be a significant threat in web applications, given their potential impact on user data confidentiality and integrity. This particular vulnerability affects versions of the WP Finance Plugin up to 1.3.6.

The vulnerability occurs due to a lack of input sanitization and escaping in a specified parameter within the plugin. This allows attackers to inject and execute malicious scripts in the form of JavaScript in the browsers of high-privileged users. The attack vector is generally through crafted URLs that manipulate the input parameters of the plugin's pages, especially used by the administrative and user interfaces. The potential exploitation happens on specific endpoints like `/wp-admin/admin.php?page=wpfinance`, where the attack can execute JavaScript payloads. The scripts can execute in the context of the victim's session on the affected WordPress site, leading to session hijacking and data exposure.

When exploited, this vulnerability can cause severe security implications for site users and admins. Attackers can hijack user sessions leading to unauthorized access to sensitive information and perform actions on behalf of the users. Additionally, it can lead to unauthorized data manipulation, defacement of the website, and other malicious activities. If administrative users are affected, the impact could also compromise the entire site, making it a severe vulnerability requiring immediate attention. Mitigating this risk involves sanitizing and escaping user inputs effectively, updating the plugin, and enforcing best security practices.

REFERENCES

Solution Advice
  • Update the WP Finance Plugin to the latest version where the vulnerability is addressed.
  • Implement proper input validation and output escaping in all vulnerable endpoints to prevent script executions.
  • Consider enabling Content Security Policy (CSP) to prevent XSS attacks by restricting sources of executable scripts.
  • Regularly perform security audits on the site to detect any additional vulnerabilities or misconfigurations.
  • Educate users and administrators on safe practices, such as avoiding clicking on suspicious links.

Get AI-powered remediation steps tailored to your asset.

Try AI Solutions →

Check your infrastructure.
Right now.

11,000+ scanners. Free to start. No credit card required.