PT-2021-16102 · WordPress · Per Page Add To Head

Prashant Karman Patel

·

Published

2021-09-13

·

Updated

2022-12-21

·

CVE-2021-24586

CVSS v3.1

4.3

Medium

VectorAV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N
Name of the Vulnerable Software and Affected Versions Per page add to head WordPress plugin versions prior to 1.4.4
Description The issue is related to the lack of CSRF checks when saving settings, which could allow attackers to make changes to the settings of a logged-in admin. Additionally, the plugin allows arbitrary HTML to be inserted in one of its settings, leading to a potential Stored XSS issue. This could be triggered in the backend, frontend, or both, depending on the payload used.
Recommendations For versions prior to 1.4.4, update to version 1.4.4 or later to resolve the issue. As a temporary workaround, consider restricting access to the plugin's settings page to minimize the risk of exploitation. Avoid using the plugin's feature that allows arbitrary HTML insertion until the issue is resolved.

Exploit

Fix

XSS

CSRF

Weakness Enumeration

Related Identifiers

CVE-2021-24586

Affected Products

Per Page Add To Head