Medium 4.4
2025-07-18< 2.3.2
Knowledge Base <= 2.3.1 - Authenticated (Administrator+) Stored Cross-Site Scripting via Plugin Slug
Minimum safe version
2.3.2
Update to 2.3.2 or later to address 5 fixable vulnerabilities
Knowledge Base <= 2.3.1 - Authenticated (Administrator+) Stored Cross-Site Scripting via Plugin Slug
WordPress Knowledge Base Plugin <= 2.3.0 is vulnerable to Cross Site Scripting (XSS)
CVE-2024-51677
WordPress Knowledge Base Plugin <= 2.1.1 is vulnerable to Cross Site Scripting (XSS)
Knowledge Base <= 2.1.1 - Authenticated (Contributor+) Stored Cross-Site Scripting via Block