Vulnerability Description
The Cryptocurrency Pricing list and Ticker WordPress plugin through 1.5 does not sanitise and escape the ccpw_setpage parameter before outputting it back in pages where its shortcode is embed, leading to a Reflected Cross-Site Scripting issue
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Premium-Themes | Cryptocurrency Pricing List And Ticker | <= 1.5 |
Related Weaknesses (CWE)
References
- https://wpscan.com/vulnerability/dc1507c1-8894-4ab6-b25f-c5e26a425b03ExploitThird Party Advisory
- https://wpscan.com/vulnerability/dc1507c1-8894-4ab6-b25f-c5e26a425b03ExploitThird Party Advisory
FAQ
What is CVE-2021-25044?
CVE-2021-25044 is a vulnerability with a CVSS score of 6.1 (MEDIUM). The Cryptocurrency Pricing list and Ticker WordPress plugin through 1.5 does not sanitise and escape the ccpw_setpage parameter before outputting it back in pages where its shortcode is embed, leading...
How severe is CVE-2021-25044?
CVE-2021-25044 has been rated MEDIUM with a CVSS base score of 6.1/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2021-25044?
Check the references section above for vendor advisories and patch information. Affected products include: Premium-Themes Cryptocurrency Pricing List And Ticker.