Vulnerability Description
The Migration, Backup, Staging WordPress plugin before 0.9.69 does not have authorisation when adding remote storages, and does not sanitise as well as escape a parameter from such unauthenticated requests before outputting it in admin page, leading to a Stored Cross-Site Scripting issue
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Wpvivid | Migration\, Backup\, Staging | < 0.9.69 |
Related Weaknesses (CWE)
References
- https://wpscan.com/vulnerability/ea74257a-f6b0-49e9-a81f-53c0eb81b1daExploitThird Party Advisory
- https://wpscan.com/vulnerability/ea74257a-f6b0-49e9-a81f-53c0eb81b1daExploitThird Party Advisory
FAQ
What is CVE-2021-24994?
CVE-2021-24994 is a vulnerability with a CVSS score of 6.1 (MEDIUM). The Migration, Backup, Staging WordPress plugin before 0.9.69 does not have authorisation when adding remote storages, and does not sanitise as well as escape a parameter from such unauthenticated req...
How severe is CVE-2021-24994?
CVE-2021-24994 has been rated MEDIUM with a CVSS base score of 6.1/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2021-24994?
Check the references section above for vendor advisories and patch information. Affected products include: Wpvivid Migration\, Backup\, Staging.