CVE-2024-11605 — The wp-publications WordPress plugin through 1.2 does not escape filenames before outputting them back in the page, which could allow high privilege users such as admin to perform Stored Cross-Site Sc — CVE Database · The Intelligence Room