Vulnerability Description
The Display Post Metadata WordPress plugin before 1.5.0 adds a shortcode to print out custom fields, however their content is not sanitised or escaped which could allow users with a role as low as Contributor to perform Cross-Site Scripting attacks
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Display Post Metadata Project | Display Post Metadata | < 1.5.0 |
Related Weaknesses (CWE)
References
- https://wpscan.com/vulnerability/49328498-d3a0-4d27-8a52-24054b5e42f3ExploitThird Party Advisory
- https://wpscan.com/vulnerability/49328498-d3a0-4d27-8a52-24054b5e42f3ExploitThird Party Advisory
FAQ
What is CVE-2021-24855?
CVE-2021-24855 is a vulnerability with a CVSS score of 5.4 (MEDIUM). The Display Post Metadata WordPress plugin before 1.5.0 adds a shortcode to print out custom fields, however their content is not sanitised or escaped which could allow users with a role as low as Con...
How severe is CVE-2021-24855?
CVE-2021-24855 has been rated MEDIUM with a CVSS base score of 5.4/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2021-24855?
Check the references section above for vendor advisories and patch information. Affected products include: Display Post Metadata Project Display Post Metadata.