Vulnerability Description
The WP RSS Aggregator WordPress plugin before 4.19.2 does not properly sanitise and escape the URL to Blacklist field, allowing malicious HTML to be inserted by high privilege users even when the unfiltered_html capability is disallowed, which could lead to Cross-Site Scripting issues.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Wprssaggregator | Wp Rss Aggregator | < 4.19.2 |
Related Weaknesses (CWE)
References
- https://wpscan.com/vulnerability/3673e13f-7ce6-4d72-b179-ae4bab55514cExploitThird Party Advisory
- https://wpscan.com/vulnerability/3673e13f-7ce6-4d72-b179-ae4bab55514cExploitThird Party Advisory
FAQ
What is CVE-2021-24768?
CVE-2021-24768 is a vulnerability with a CVSS score of 4.8 (MEDIUM). The WP RSS Aggregator WordPress plugin before 4.19.2 does not properly sanitise and escape the URL to Blacklist field, allowing malicious HTML to be inserted by high privilege users even when the unfi...
How severe is CVE-2021-24768?
CVE-2021-24768 has been rated MEDIUM with a CVSS base score of 4.8/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2021-24768?
Check the references section above for vendor advisories and patch information. Affected products include: Wprssaggregator Wp Rss Aggregator.