Vulnerability Description
The Language Bar Flags WordPress plugin through 1.0.8 does not have any CSRF in place when saving its settings and did not sanitise or escape them when generating the flag bar in the frontend. This could allow attackers to make a logged in admin change the settings, and set Cross-Site Scripting payload in them, which will be executed in the frontend for all users
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Language Bar Flags Project | Language Bar Flags | <= 1.0.8 |
Related Weaknesses (CWE)
References
- https://wpscan.com/vulnerability/ae50cec9-5f80-4221-b6a8-4593ab66c37bExploitThird Party Advisory
- https://wpscan.com/vulnerability/ae50cec9-5f80-4221-b6a8-4593ab66c37bExploitThird Party Advisory
FAQ
What is CVE-2021-24431?
CVE-2021-24431 is a vulnerability with a CVSS score of 4.3 (MEDIUM). The Language Bar Flags WordPress plugin through 1.0.8 does not have any CSRF in place when saving its settings and did not sanitise or escape them when generating the flag bar in the frontend. This co...
How severe is CVE-2021-24431?
CVE-2021-24431 has been rated MEDIUM with a CVSS base score of 4.3/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2021-24431?
Check the references section above for vendor advisories and patch information. Affected products include: Language Bar Flags Project Language Bar Flags.