Vulnerability Description
The WP Customer Reviews WordPress plugin before 3.5.6 did not sanitise some of its settings, allowing high privilege users such as administrators to set XSS payloads in them which will then be triggered in pages where reviews are enabled
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Gowebsolutions | Wp Customer Reviews | < 3.5.6 |
Related Weaknesses (CWE)
References
- https://wpscan.com/vulnerability/c450f54a-3372-49b2-8ad8-68d5cc0dd49eExploitThird Party Advisory
- https://wpscan.com/vulnerability/c450f54a-3372-49b2-8ad8-68d5cc0dd49eExploitThird Party Advisory
FAQ
What is CVE-2021-24296?
CVE-2021-24296 is a vulnerability with a CVSS score of 4.8 (MEDIUM). The WP Customer Reviews WordPress plugin before 3.5.6 did not sanitise some of its settings, allowing high privilege users such as administrators to set XSS payloads in them which will then be trigger...
How severe is CVE-2021-24296?
CVE-2021-24296 has been rated MEDIUM with a CVSS base score of 4.8/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2021-24296?
Check the references section above for vendor advisories and patch information. Affected products include: Gowebsolutions Wp Customer Reviews.