Vulnerability Description
Unvalidated input and lack of output encoding in the Themify Portfolio Post WordPress plugin, versions before 1.1.6, lead to Stored Cross-Site Scripting (XSS) vulnerabilities allowing low-privileged users (Contributor+) to inject arbitrary JavaScript code or HTML in posts where the Themify Custom Panel is embedded, which could lead to privilege escalation.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Themify | Portfolio Post | < 1.1.6 |
Related Weaknesses (CWE)
References
- https://wpscan.com/vulnerability/c8537e5f-1948-418b-9d29-3cf50cd8f9a6ExploitThird Party Advisory
- https://wpscan.com/vulnerability/c8537e5f-1948-418b-9d29-3cf50cd8f9a6ExploitThird Party Advisory
FAQ
What is CVE-2021-24129?
CVE-2021-24129 is a vulnerability with a CVSS score of 5.4 (MEDIUM). Unvalidated input and lack of output encoding in the Themify Portfolio Post WordPress plugin, versions before 1.1.6, lead to Stored Cross-Site Scripting (XSS) vulnerabilities allowing low-privileged u...
How severe is CVE-2021-24129?
CVE-2021-24129 has been rated MEDIUM with a CVSS base score of 5.4/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2021-24129?
Check the references section above for vendor advisories and patch information. Affected products include: Themify Portfolio Post.