PT-2021-16097 · WordPress · Blue Admin
Abisheik M
·
Published
2021-08-30
·
Updated
2023-02-11
·
CVE-2021-24581
CVSS v3.1
8.8
High
| Vector | AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
The Blue Admin WordPress plugin versions through 21.06.01
Description
The issue is related to a Stored Cross-Site Scripting problem. The plugin does not sanitise or escape its
Logo Title setting before outputting it in a page. Additionally, the plugin lacks a CSRF check when saving its settings, allowing the issue to be exploited via a CSRF attack.Recommendations
For versions through 21.06.01, update to a version that addresses the Stored Cross-Site Scripting issue and implements a CSRF check for saving settings. As a temporary workaround, consider disabling the
Logo Title setting until a patch is available. Restrict access to the plugin's settings to minimize the risk of exploitation.Exploit
Fix
XSS
CSRF
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Blue Admin