CVE-2021-24135: WP Customer Reviews < 3.4.3 - Multiple Unauthenticated and Low Priv Authenticated Stored XSS
Unvalidated input and lack of output encoding in the WP Customer Reviews WordPress plugin, versions before 3.4.3, lead to multiple Stored Cross-Site Scripting vulnerabilities allowing remote attackers to inject arbitrary JavaScript code or HTML.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2021-24135?
CVE-2021-24135 is a vulnerability in the WP Customer Reviews WordPress plugin that allows remote attackers to inject arbitrary JavaScript code or HTML.
How severe is CVE-2021-24135?
CVE-2021-24135 has a severity value of 6.1, which is considered medium.
Which versions of the WP Customer Reviews plugin are affected by CVE-2021-24135?
Versions of the WP Customer Reviews plugin before 3.4.3 are affected by CVE-2021-24135.
What is the CWE classification for CVE-2021-24135?
CVE-2021-24135 is classified under CWE-79, which is for Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting').
How can I fix CVE-2021-24135?
To fix CVE-2021-24135, update the WP Customer Reviews plugin to version 3.4.3 or later.