Description
The Current Book WordPress plugin through 1.0.1 does not sanitize user input when an authenticated user adds Author or Book Title, then does not escape these values when outputting to the browser leading to an Authenticated Stored XSS Cross-Site Scripting issue.
Published: 2021-08-16
Score: 5.4 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

No analysis available yet.

Remediation

No remediation available yet.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
EUVD EUVD EUVD-2021-11450 The Current Book WordPress plugin through 1.0.1 does not sanitize user input when an authenticated user adds Author or Book Title, then does not escape these values when outputting to the browser leading to an Authenticated Stored XSS Cross-Site Scripting issue.
History

No history.

Subscriptions

Current Book Project Current Book
cve-icon MITRE

Status: PUBLISHED

Assigner: WPScan

Published:

Updated: 2024-08-03T19:35:20.035Z

Reserved: 2021-01-14T00:00:00.000Z

Link: CVE-2021-24538

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Modified

Published: 2021-08-16T11:15:09.107

Modified: 2024-11-21T05:53:15.620

Link: CVE-2021-24538

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.

Weaknesses