Vulnerability Description
The Social Tape WordPress plugin through 1.0 does not have CSRF checks in place when saving its settings, and do not sanitise or escape them before outputting them back in the page, leading to a stored Cross-Site Scripting issue via a CSRF attack
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Social Tape Project | Social Tape | <= 1.0 |
Related Weaknesses (CWE)
References
- https://wpscan.com/vulnerability/ebe7f625-67e1-4df5-a569-20526dd57b24ExploitThird Party Advisory
- https://wpscan.com/vulnerability/ebe7f625-67e1-4df5-a569-20526dd57b24ExploitThird Party Advisory
FAQ
What is CVE-2021-24411?
CVE-2021-24411 is a vulnerability with a CVSS score of 6.1 (MEDIUM). The Social Tape WordPress plugin through 1.0 does not have CSRF checks in place when saving its settings, and do not sanitise or escape them before outputting them back in the page, leading to a store...
How severe is CVE-2021-24411?
CVE-2021-24411 has been rated MEDIUM with a CVSS base score of 6.1/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2021-24411?
Check the references section above for vendor advisories and patch information. Affected products include: Social Tape Project Social Tape.