PT-2021-15950 · WordPress · Smooth Scroll Page Up/Down Buttons

M0Ze

+1

·

Published

2021-07-12

·

Updated

2021-07-15

·

CVE-2021-24418

CVSS v3.1

4.8

Medium

VectorAV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions Smooth Scroll Page Up/Down Buttons WordPress plugin versions 1.4 and earlier
Description The issue allows high privilege users, such as admins, to set an XSS payload in the psb positioning settings, which will be executed in all pages of the blog. This occurs due to the plugin's failure to properly sanitise and validate its settings.
Recommendations For Smooth Scroll Page Up/Down Buttons WordPress plugin versions 1.4 and earlier, update to a version that properly sanitises and validates the psb positioning settings to prevent XSS payload execution.

Exploit

Fix

XSS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2021-24418

Affected Products

Smooth Scroll Page Up/Down Buttons