CVE-2021-24564
WPFront Scroll Top < 2.0.6.07225 - Authenticated Stored XSS
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
1Exploited in Wild
-Decision
Descriptions
The WPFront Scroll Top WordPress plugin before 2.0.6.07225 does not sanitise or escape its Image ALT setting before outputting it attributes, leading to an Authenticated Stored Cross-Site Scripting issues even when the unfiltered_html capability is disallowed.
El plugin de WordPress WPFront Scroll Top versiones anteriores a 2.0.6.07225, no sanea ni escapa de su configuración de ALT de imagen antes de emitirla en atributos, conllevando a un problema de tipo Cross-Site Scripting Almacenado y Autenticado incluso cuando la capacidad unfiltered_html no está permitida.
The WPFront Scroll Top WordPress plugin before 2.0.5 does not sanitise or escape its Image ALT setting before outputting it attributes, leading to an Authenticated Stored Cross-Site Scripting issues even when the unfiltered_html capability is disallowed.
CVSS Scores
SSVC
- Decision:-
Timeline
- 2021-01-14 CVE Reserved
- 2021-07-26 CVE Published
- 2023-03-16 EPSS Updated
- 2024-08-03 CVE Updated
- 2024-08-03 First Exploit
- ---------- Exploited in Wild
- ---------- KEV Due Date
CWE
- CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CAPEC
References (1)
URL | Tag | Source |
---|
URL | Date | SRC |
---|---|---|
https://wpscan.com/vulnerability/b25af0e1-392f-4305-ad44-50e64ef3dbdf | 2024-08-03 |
URL | Date | SRC |
---|
URL | Date | SRC |
---|
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Wpfront Search vendor "Wpfront" | Scroll Top Search vendor "Wpfront" for product "Scroll Top" | < 2.0.6.07225 Search vendor "Wpfront" for product "Scroll Top" and version " < 2.0.6.07225" | wordpress |
Affected
|