PT-2021-15976 · WordPress · Profilepress

Keyloggervk7

+1

·

Published

2021-08-02

·

Updated

2023-05-26

·

CVE-2021-24450

CVSS v3.1

4.8

Medium

VectorAV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions User Registration, User Profiles, Login & Membership – ProfilePress (Formerly WP User Avatar) WordPress plugin versions prior to 3.1.8
Description The issue allows high privilege users, such as admins, to set JavaScript payloads in some settings, even when the unfiltered html capability is disallowed, leading to an authenticated Stored Cross-Site Scripting issue. This occurs because the plugin does not properly sanitise or escape some of its settings before saving and outputting them back in the page.
Recommendations For versions prior to 3.1.8, update to version 3.1.8 or later to resolve the issue. As a temporary workaround, consider restricting the ability of high privilege users to modify settings that could be used to inject JavaScript payloads.

Exploit

Fix

XSS

Weakness Enumeration

Related Identifiers

CVE-2021-24450

Affected Products

Profilepress