Vulnerability Description
The Wonder PDF Embed WordPress plugin before 1.7 does not escape parameters of its wonderplugin_pdf shortcode, which could allow users with a role as low as Contributor to perform Stored XSS attacks.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Wonderplugin | Wonder Pdf Embed | < 1.7 |
Related Weaknesses (CWE)
References
- https://wpscan.com/vulnerability/e6602369-87f4-4454-8298-89cc69f8375cExploitThird Party Advisory
- https://wpscan.com/vulnerability/e6602369-87f4-4454-8298-89cc69f8375cExploitThird Party Advisory
FAQ
What is CVE-2021-24541?
CVE-2021-24541 is a vulnerability with a CVSS score of 5.4 (MEDIUM). The Wonder PDF Embed WordPress plugin before 1.7 does not escape parameters of its wonderplugin_pdf shortcode, which could allow users with a role as low as Contributor to perform Stored XSS attacks.
How severe is CVE-2021-24541?
CVE-2021-24541 has been rated MEDIUM with a CVSS base score of 5.4/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2021-24541?
Check the references section above for vendor advisories and patch information. Affected products include: Wonderplugin Wonder Pdf Embed.