CVE-2021-24287
MEDIUM 6.1EPSS 10.4%
The settings page of the Select All Categories and Taxonomies, Change Checkbox to Radio Buttons WordPress plugin before 1.3.2 did not properly sanitise the tab parameter before outputting it back, leading to a reflected Cross-Site Scripting issue
- CVSS v3.1
- 6.1 MEDIUM
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N - CVSS v2.0
- 4.3 MEDIUM
AV:N/AC:M/Au:N/C:N/I:P/A:N - EPSS
- 10.36% chance of exploitation in the next 30 days, 95th percentile
- Nuclei
- medium · CWE-79
- Published
- 2021-05-14
- Updated
- 2024-08-03
Proof-of-concept exploits (2)
- http://packetstormsecurity.com/files/164327/WordPress-Select-All-Categories-And-Taxonomie…
- https://wpscan.com/vulnerability/56e1bb56-bfc5-40dd-b2d0-edef43d89bdf