CVE-2024-11202: Creativemindssolutions Cm Business Directory – Optimise And Showcase Local Business

Medium severity, CVSS 6.1. EPSS: 0.6% chance of exploitation in the next 30 days.

Multiple plugins for WordPress are vulnerable to Reflected Cross-Site Scripting via the cminds_free_guide shortcode in various versions due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a link.

Affected products

  • Creativemindssolutions Cm Business Directory – Optimise And Showcase Local Business: up to and including 1.4.1
  • Creativemindssolutions Cm E-Mail Blacklist – Simple Email Filtering For Safer Registration: up to and including 1.5.3
  • Creativemindssolutions Cm Header And Footer – Add Custom Scripts And Styles To Your Header And Footer With Ease: up to and including 1.2.1
  • Creativemindssolutions Cm Pop-Up – Create Engaging Popups To Capture Attention And Boost Interaction: up to and including 1.7.5
  • Creativemindssolutions Cm Search And Replace – Optimize Content Edits With A Powerful Search And Replace Tool: up to and including 1.4.2
  • Creativemindssolutions Cm Tooltip Glossary: up to and including 4.3.11
  • Creativemindssolutions Cm Video Lessons Manager – Simplify Video Lessons Management For Better Education: up to and including 1.8.2

Published 2024-11-26. Last modified 2026-06-17.