Vulnerability Description
The WP Offload SES Lite WordPress plugin before 1.4.5 did not escape some of the fields in the Activity page of the admin dashboard, such as the email's id, subject and recipient, which could lead to Stored Cross-Site Scripting issues when an attacker can control any of these fields, like the subject when filling a contact form for example. The XSS will be executed in the context of a logged in admin viewing the Activity tab of the plugin.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Deliciousbrains | Wp Offload Ses Lite | < 1.4.5 |
Related Weaknesses (CWE)
References
- https://wpscan.com/vulnerability/8f14733e-84c3-4f7c-93f8-e27c74519160ExploitVendor Advisory
- https://wpscan.com/vulnerability/8f14733e-84c3-4f7c-93f8-e27c74519160ExploitVendor Advisory
FAQ
What is CVE-2021-24494?
CVE-2021-24494 is a vulnerability with a CVSS score of 5.4 (MEDIUM). The WP Offload SES Lite WordPress plugin before 1.4.5 did not escape some of the fields in the Activity page of the admin dashboard, such as the email's id, subject and recipient, which could lead to ...
How severe is CVE-2021-24494?
CVE-2021-24494 has been rated MEDIUM with a CVSS base score of 5.4/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2021-24494?
Check the references section above for vendor advisories and patch information. Affected products include: Deliciousbrains Wp Offload Ses Lite.