PT-2021-16102 · WordPress · Per Page Add To Head
Prashant Karman Patel
·
Published
2021-09-13
·
Updated
2022-12-21
·
CVE-2021-24586
CVSS v3.1
4.3
Medium
| Vector | AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
Per page add to head WordPress plugin versions prior to 1.4.4
Description
The issue is related to the lack of CSRF checks when saving settings, which could allow attackers to make changes to the settings of a logged-in admin. Additionally, the plugin allows arbitrary HTML to be inserted in one of its settings, leading to a potential Stored XSS issue. This could be triggered in the backend, frontend, or both, depending on the payload used.
Recommendations
For versions prior to 1.4.4, update to version 1.4.4 or later to resolve the issue. As a temporary workaround, consider restricting access to the plugin's settings page to minimize the risk of exploitation. Avoid using the plugin's feature that allows arbitrary HTML insertion until the issue is resolved.
Exploit
Fix
XSS
CSRF
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Per Page Add To Head