Vulnerability Description
The Yada Wiki WordPress plugin before 3.4.1 did not sanitise, validate or escape the anchor attribute of its shortcode, leading to a Stored Cross-Site Scripting issue
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Yada Wiki Project | Yada Wiki | < 3.4.1 |
Related Weaknesses (CWE)
References
- https://wpscan.com/vulnerability/b01a85cc-0e45-4183-a916-19476354d5d4Third Party Advisory
- https://wpscan.com/vulnerability/b01a85cc-0e45-4183-a916-19476354d5d4Third Party Advisory
FAQ
What is CVE-2021-24470?
CVE-2021-24470 is a vulnerability with a CVSS score of 5.4 (MEDIUM). The Yada Wiki WordPress plugin before 3.4.1 did not sanitise, validate or escape the anchor attribute of its shortcode, leading to a Stored Cross-Site Scripting issue
How severe is CVE-2021-24470?
CVE-2021-24470 has been rated MEDIUM with a CVSS base score of 5.4/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2021-24470?
Check the references section above for vendor advisories and patch information. Affected products include: Yada Wiki Project Yada Wiki.