Vulnerability Description
The Enfold Enfold WordPress theme before 4.8.4 was vulnerable to Reflected Cross-Site Scripting (XSS). The vulnerability is present on Enfold versions previous than 4.8.4 which use Avia Page Builder.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Kriesi | Enfold | < 4.8.4 |
Related Weaknesses (CWE)
References
- http://packetstormsecurity.com/files/164548/WordPress-Enfold-Theme-4.8.3-Cross-SExploitThird Party AdvisoryVDB Entry
- https://wpscan.com/vulnerability/a53e213f-6011-47f8-93e6-aa5ad30e857eExploitThird Party Advisory
- http://packetstormsecurity.com/files/164548/WordPress-Enfold-Theme-4.8.3-Cross-SExploitThird Party AdvisoryVDB Entry
- https://wpscan.com/vulnerability/a53e213f-6011-47f8-93e6-aa5ad30e857eExploitThird Party Advisory
FAQ
What is CVE-2021-24719?
CVE-2021-24719 is a vulnerability with a CVSS score of 6.1 (MEDIUM). The Enfold Enfold WordPress theme before 4.8.4 was vulnerable to Reflected Cross-Site Scripting (XSS). The vulnerability is present on Enfold versions previous than 4.8.4 which use Avia Page Builder.
How severe is CVE-2021-24719?
CVE-2021-24719 has been rated MEDIUM with a CVSS base score of 6.1/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2021-24719?
Check the references section above for vendor advisories and patch information. Affected products include: Kriesi Enfold.