CVE-2021-24211

The WordPress Related Posts plugin through 3.6.4 contains an authenticated (admin+) stored XSS vulnerability in the title field on the settings page. By exploiting that an attacker will be able to execute JavaScript code in the user's browser.
References
Advertisement

NeevaHost hosting service

Configurations

Configuration 1 (hide)

cpe:2.3:a:wphive:wordpress_related_posts:*:*:*:*:*:wordpress:*:*

Information

Published : 2021-04-05 12:15

Updated : 2021-04-12 05:57


NVD link : CVE-2021-24211

Mitre link : CVE-2021-24211


JSON object : View

CWE
CWE-79

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

Advertisement

dedicated server usa

Products Affected

wphive

  • wordpress_related_posts