CVE-2021-24287
Summary
| CVE | CVE-2021-24287 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2021-05-14 12:15:00 UTC |
| Updated | 2021-10-18 11:51:00 UTC |
| Description | The settings page of the Select All Categories and Taxonomies, Change Checkbox to Radio Buttons WordPress plugin before 1.3.2 did not properly sanitise the tab parameter before outputting it back, leading to a reflected Cross-Site Scripting issue |
Risk And Classification
Problem Types: CWE-79
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Mooveagency | Select All Categories And Taxonomies Change Checkbox To Radio Buttons | All | All | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| WordPress Select All Categories And Taxonomies 1.3.1 Cross Site Scripting ≈ Packet Storm | MISC | packetstormsecurity.com | |
| Attention Required! | Cloudflare | CONFIRM | wpscan.com | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
Vendor Comments And Credit
Discovery Credit
LEGACY: 0xB9
There are currently no legacy QID mappings associated with this CVE.