Vulnerability Description
The Site Reviews WordPress plugin before 5.13.1 does not sanitise some of its Review Details when adding a review as an admin, which could allow them to perform Cross-Site Scripting attacks when the unfiltered_html is disallowed
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Geminilabs | Site Reviews | < 5.13.1 |
Related Weaknesses (CWE)
References
- https://wpscan.com/vulnerability/72aea0e5-1fa7-4827-a173-59982202d323ExploitThird Party Advisory
- https://wpscan.com/vulnerability/72aea0e5-1fa7-4827-a173-59982202d323ExploitThird Party Advisory
FAQ
What is CVE-2021-24603?
CVE-2021-24603 is a vulnerability with a CVSS score of 5.4 (MEDIUM). The Site Reviews WordPress plugin before 5.13.1 does not sanitise some of its Review Details when adding a review as an admin, which could allow them to perform Cross-Site Scripting attacks when the u...
How severe is CVE-2021-24603?
CVE-2021-24603 has been rated MEDIUM with a CVSS base score of 5.4/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2021-24603?
Check the references section above for vendor advisories and patch information. Affected products include: Geminilabs Site Reviews.