Description
Authenticated Stored Cross-Site Scripting (XSS) vulnerability in YITH Maintenance Mode (WordPress plugin) versions <= 1.3.7, vulnerable parameter &yith_maintenance_newsletter_submit_label. Possible even when unfiltered HTML is disallowed by WordPress configuration.
No analysis available yet.
Remediation
Vendor Solution
Update to 1.3.8 or higher version.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2021-23417 | Authenticated Stored Cross-Site Scripting (XSS) vulnerability in YITH Maintenance Mode (WordPress plugin) versions <= 1.3.7, vulnerable parameter &yith_maintenance_newsletter_submit_label. Possible even when unfiltered HTML is disallowed by WordPress configuration. |
References
History
Fri, 28 Mar 2025 17:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Status: PUBLISHED
Assigner: Patchstack
Published:
Updated: 2026-04-28T16:07:32.849Z
Reserved: 2021-07-19T00:00:00.000Z
Link: CVE-2021-36841
Updated: 2024-08-04T01:01:59.890Z
Status : Modified
Published: 2021-09-27T16:15:09.327
Modified: 2024-11-21T06:14:10.560
Link: CVE-2021-36841
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD