Vulnerability Description
The ShareThis Dashboard for Google Analytics WordPress plugin before 2.5.2 does not sanitise or escape the 'ga_action' parameter in the stats view before outputting it back in an attribute when the plugin is connected to a Google Analytics account, leading to a reflected Cross-Site Scripting issue which will be executed in the context of a logged in administrator
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Sharethis | Dashboard For Google Analytics | < 2.5.2 |
Related Weaknesses (CWE)
References
- https://wpscan.com/vulnerability/af472879-9328-45c2-957f-e7bed77e4c2dExploitThird Party Advisory
- https://wpscan.com/vulnerability/af472879-9328-45c2-957f-e7bed77e4c2dExploitThird Party Advisory
FAQ
What is CVE-2021-24438?
CVE-2021-24438 is a vulnerability with a CVSS score of 6.1 (MEDIUM). The ShareThis Dashboard for Google Analytics WordPress plugin before 2.5.2 does not sanitise or escape the 'ga_action' parameter in the stats view before outputting it back in an attribute when the pl...
How severe is CVE-2021-24438?
CVE-2021-24438 has been rated MEDIUM with a CVSS base score of 6.1/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2021-24438?
Check the references section above for vendor advisories and patch information. Affected products include: Sharethis Dashboard For Google Analytics.