Vulnerability Description
The Special Text Boxes WordPress plugin before 5.9.110 does not sanitise or escape some of its settings, which could allow high privilege users to perform Cross-Site Scripting attacks even when the unfiltered_html is disallowed.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Wp-Special-Textboxes Project | Wp-Special-Textboxes | < 5.9.110 |
Related Weaknesses (CWE)
References
- https://wpscan.com/vulnerability/4a6b278a-4c11-4624-86bf-754212979643ExploitThird Party Advisory
- https://wpscan.com/vulnerability/4a6b278a-4c11-4624-86bf-754212979643ExploitThird Party Advisory
FAQ
What is CVE-2021-24485?
CVE-2021-24485 is a vulnerability with a CVSS score of 4.8 (MEDIUM). The Special Text Boxes WordPress plugin before 5.9.110 does not sanitise or escape some of its settings, which could allow high privilege users to perform Cross-Site Scripting attacks even when the un...
How severe is CVE-2021-24485?
CVE-2021-24485 has been rated MEDIUM with a CVSS base score of 4.8/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2021-24485?
Check the references section above for vendor advisories and patch information. Affected products include: Wp-Special-Textboxes Project Wp-Special-Textboxes.