Vulnerability Description
The Custom Content Shortcode WordPress plugin before 4.0.2 does not escape custom fields before outputting them, which could allow Contributor+ (v < 4.0.1) or Admin+ (v < 4.0.2) users to perform Cross-Site Scripting attacks even when the unfiltered_html is disallowed. Please note that such attack is still possible by admin+ in single site blogs by default (but won't be when the unfiltered_html is disallowed)
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Custom Content Shortcode Project | Custom Content Shortcode | < 4.0.2 |
Related Weaknesses (CWE)
References
- https://wpscan.com/vulnerability/e247d78a-7243-486c-a017-7471a8dcb800ExploitThird Party Advisory
- https://wpscan.com/vulnerability/e247d78a-7243-486c-a017-7471a8dcb800ExploitThird Party Advisory
FAQ
What is CVE-2021-24826?
CVE-2021-24826 is a vulnerability with a CVSS score of 5.4 (MEDIUM). The Custom Content Shortcode WordPress plugin before 4.0.2 does not escape custom fields before outputting them, which could allow Contributor+ (v < 4.0.1) or Admin+ (v < 4.0.2) users to perform Cross...
How severe is CVE-2021-24826?
CVE-2021-24826 has been rated MEDIUM with a CVSS base score of 5.4/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2021-24826?
Check the references section above for vendor advisories and patch information. Affected products include: Custom Content Shortcode Project Custom Content Shortcode.