PT-2021-16000 · WordPress · Migrate Users Wordpress Plugin
Abisheik M
·
Published
2021-08-02
·
Updated
2021-09-21
·
CVE-2021-24477
CVSS v3.1
6.1
Medium
| Vector | AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
Migrate Users WordPress plugin versions prior to 1.1.2 is not specified, however, the plugin through 1.0.1 is affected.
Description
The issue is related to a Stored Cross-Site Scripting problem. This occurs because the Delimiter option is not properly sanitised or escaped before being outputted on a page. Additionally, the plugin lacks a CSRF check when saving its options, making it possible for the issue to be exploited through a CSRF attack.
Recommendations
For Migrate Users WordPress plugin versions through 1.0.1, update to a version that addresses the Stored Cross-Site Scripting issue and implements a CSRF check.
Exploit
Fix
XSS
CSRF
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Migrate Users Wordpress Plugin