PT-2021-16059 · WordPress · The Current Book Wordpress Plugin
007Vikaxh
+1
·
Published
2021-08-16
·
Updated
2021-08-23
·
CVE-2021-24538
CVSS v3.1
5.4
Medium
| Vector | AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
The Current Book WordPress plugin versions 1.0.1 and earlier
Description
The issue arises from the plugin's failure to sanitize user input when an authenticated user adds an Author or Book Title. This lack of sanitization, combined with the failure to escape these values when outputting to the browser, leads to an Authenticated Stored XSS Cross-Site Scripting issue.
Recommendations
For versions 1.0.1 and earlier, update to a version that properly sanitizes user input and escapes output values to prevent XSS attacks. As a temporary workaround, consider restricting the ability of authenticated users to add Author or Book Title entries until a patch is available.
Exploit
Fix
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
The Current Book Wordpress Plugin