PT-2021-15958 · WordPress · Rss For Yandex Turbo
M0Ze
+1
·
Published
2021-08-02
·
Updated
2021-08-09
·
CVE-2021-24428
CVSS v3.1
4.8
Medium
| Vector | AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
RSS for Yandex Turbo WordPress plugin versions 1.30 and earlier
Description
The issue is related to an Authenticated Stored Cross-Site Scripting problem. It occurs because some settings are not properly sanitised or escaped before being saved and output in the admin dashboard. This can happen even when the unfiltered html capability is disallowed.
Recommendations
For RSS for Yandex Turbo WordPress plugin versions 1.30 and earlier, update to a version later than 1.30 to resolve the issue.
At the moment, there is no information about other versions that contain a fix for this issue.
Fix
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Rss For Yandex Turbo