PT-2021-15867 · Cartflows · The Funnel Builder By Cartflows

M0Ze

+1

·

Published

2021-06-01

·

Updated

2023-08-09

·

CVE-2021-24330

CVSS v3.1

4.8

Medium

VectorAV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions The Funnel Builder by CartFlows – Create High Converting Sales Funnels For WordPress plugin versions prior to 1.6.13
Description The issue concerns the plugin's failure to sanitize its facebook pixel id and google analytics id settings, allowing high-privilege users to set XSS payload in them. This can lead to the execution of the payload on pages generated by the plugin or the whole website, depending on the settings used.
Recommendations For versions prior to 1.6.13, update to version 1.6.13 or later to resolve the issue. As a temporary workaround, consider restricting access to the facebook pixel id and google analytics id settings to prevent high-privilege users from setting XSS payloads.

Exploit

Fix

XSS

Weakness Enumeration

Related Identifiers

CVE-2021-24330

Affected Products

The Funnel Builder By Cartflows