CVE-2021-24127: ThirstyAffiliates < 3.9.3 - Authenticated Stored XSS
Published Mar 18, 2021
·Updated
Unvalidated input and lack of output encoding in the ThirstyAffiliates Affiliate Link Manager WordPress plugin, versions before 3.9.3, was vulnerable to authenticated Stored Cross-Site Scripting (XSS), which could lead to privilege escalation.
Affected Software
1 affected component
Caseproof Thirstyaffiliates Affiliate Link Manager Wordpress<3.9.3
Event History
Mar 18, 2021
CVE Published
via MITRE·02:57 PM
Data Sourced
via MITRE·02:57 PM
DescriptionWeakness
Frequently Asked Questions
1
What is the severity of CVE-2021-24127?
CVE-2021-24127 has a medium severity rating due to the potential for authenticated Stored Cross-Site Scripting (XSS) attacks.
2
How do I fix CVE-2021-24127?
To fix CVE-2021-24127, update the ThirstyAffiliates Affiliate Link Manager plugin to version 3.9.3 or later.
3
What types of attacks can CVE-2021-24127 lead to?
CVE-2021-24127 can lead to privilege escalation through authenticated Stored Cross-Site Scripting exploits.
4
Which versions of the ThirstyAffiliates Affiliate Link Manager are affected by CVE-2021-24127?
CVE-2021-24127 affects versions of the ThirstyAffiliates Affiliate Link Manager prior to 3.9.3.
5
Is user authentication required to exploit CVE-2021-24127?
Yes, exploitation of CVE-2021-24127 requires authenticated user access.