Vulnerability Description
The Storefront Footer Text WordPress plugin through 1.0.1 does not sanitize and escape the "Footer Credit Text" added to pages, allowing high privilege users to perform Cross-Site Scripting attacks even when the unfiltered-html capability is disallowed.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Wooassist | Storefront Footer Text | <= 1.0.1 |
Related Weaknesses (CWE)
References
- https://wpscan.com/vulnerability/efa7d91a-447b-4fd8-aa21-5364b177fee9ExploitThird Party Advisory
- https://wpscan.com/vulnerability/efa7d91a-447b-4fd8-aa21-5364b177fee9ExploitThird Party Advisory
FAQ
What is CVE-2021-24607?
CVE-2021-24607 is a vulnerability with a CVSS score of 4.8 (MEDIUM). The Storefront Footer Text WordPress plugin through 1.0.1 does not sanitize and escape the "Footer Credit Text" added to pages, allowing high privilege users to perform Cross-Site Scripting attacks ev...
How severe is CVE-2021-24607?
CVE-2021-24607 has been rated MEDIUM with a CVSS base score of 4.8/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2021-24607?
Check the references section above for vendor advisories and patch information. Affected products include: Wooassist Storefront Footer Text.