CVE-2021-24485

The Special Text Boxes WordPress plugin before 5.9.110 does not sanitise or escape some of its settings, which could allow high privilege users to perform Cross-Site Scripting attacks even when the unfiltered_html is disallowed.
References
Configurations

Configuration 1 (hide)

cpe:2.3:a:wp-special-textboxes_project:wp-special-textboxes:*:*:*:*:*:wordpress:*:*

History

04 Jul 2022, 13:15

Type Values Removed Values Added
Summary The Special Text Boxes WordPress plugin through 5.9.109 does not sanitise or escape some of its settings, which could allow high privilege users to perform Cross-Site Scripting attacks even when the unfiltered_html is disallowed. The Special Text Boxes WordPress plugin before 5.9.110 does not sanitise or escape some of its settings, which could allow high privilege users to perform Cross-Site Scripting attacks even when the unfiltered_html is disallowed.

28 Oct 2021, 14:23

Type Values Removed Values Added
References (MISC) https://wpscan.com/vulnerability/4a6b278a-4c11-4624-86bf-754212979643 - (MISC) https://wpscan.com/vulnerability/4a6b278a-4c11-4624-86bf-754212979643 - Exploit, Third Party Advisory
CPE cpe:2.3:a:wp-special-textboxes_project:wp-special-textboxes:*:*:*:*:*:wordpress:*:*
CVSS v2 : unknown
v3 : unknown
v2 : 3.5
v3 : 4.8

25 Oct 2021, 15:34

Type Values Removed Values Added
New CVE

Information

Published : 2021-10-25 14:15

Updated : 2024-02-04 22:08


NVD link : CVE-2021-24485

Mitre link : CVE-2021-24485

CVE.ORG link : CVE-2021-24485


JSON object : View

Products Affected

wp-special-textboxes_project

  • wp-special-textboxes
CWE
CWE-79

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')