PT-2021-16114 · WordPress · The Email Encoder – Protect Email Addresses

Dc11

·

Published

2021-09-06

·

Updated

2021-09-10

·

CVE-2021-24599

CVSS v3.1

6.1

Medium

VectorAV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions The Email Encoder – Protect Email Addresses WordPress plugin versions prior to 2.1.2
Description The issue concerns an endpoint that requires no authentication and will render a user-supplied value in the HTML response without escaping or sanitizing the data. This allows for potential exploitation.
Recommendations For versions prior to 2.1.2, update to version 2.1.2 or later to resolve the issue. As a temporary workaround, consider restricting access to the vulnerable endpoint until a patch is applied.

Exploit

Fix

XSS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2021-24599

Affected Products

The Email Encoder – Protect Email Addresses