Vulnerability Description
The UpdraftPlus WordPress Backup Plugin WordPress plugin before 1.6.59 does not sanitise its updraft_service settings, allowing high privilege users to set malicious JavaScript payload in it and leading to a Stored Cross-Site Scripting issue
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Updraftplus | Updraftplus | < 1.16.59 |
Related Weaknesses (CWE)
References
- https://m0ze.ru/vulnerability/%5B2021-05-09%5D-%5BWordPress%5D-%5BCWE-79%5D-Updr
- https://wpscan.com/vulnerability/541974d6-2df8-4497-9aee-afd3b9024102ExploitThird Party Advisory
- https://m0ze.ru/vulnerability/%5B2021-05-09%5D-%5BWordPress%5D-%5BCWE-79%5D-Updr
- https://wpscan.com/vulnerability/541974d6-2df8-4497-9aee-afd3b9024102ExploitThird Party Advisory
FAQ
What is CVE-2021-24423?
CVE-2021-24423 is a vulnerability with a CVSS score of 4.8 (MEDIUM). The UpdraftPlus WordPress Backup Plugin WordPress plugin before 1.6.59 does not sanitise its updraft_service settings, allowing high privilege users to set malicious JavaScript payload in it and leadi...
How severe is CVE-2021-24423?
CVE-2021-24423 has been rated MEDIUM with a CVSS base score of 4.8/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2021-24423?
Check the references section above for vendor advisories and patch information. Affected products include: Updraftplus Updraftplus.