PT-2021-16127 · WordPress · Keyword Meta Wordpress Plugin
Genubhau Wayal
·
Published
2021-09-06
·
Updated
2021-09-13
·
CVE-2021-24611
CVSS v3.1
5.4
Medium
| Vector | AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
Keyword Meta WordPress plugin versions 3.0 and earlier
Description
The issue arises from the plugin's failure to sanitise or escape its settings before outputting them, leading to Cross-Site Scripting issues. Additionally, the lack of a CSRF check allows attackers to manipulate logged-in high-privilege users into saving arbitrary settings via a CSRF attack.
Recommendations
For versions 3.0 and earlier, update to a version that addresses the sanitisation and CSRF issues.
As a temporary workaround, consider restricting access to the plugin's settings page to minimize the risk of exploitation.
Avoid using the plugin until a patched version is available.
Exploit
Fix
XSS
CSRF
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Keyword Meta Wordpress Plugin