First published: Thu Mar 18 2021(Updated: )
Unvalidated input and lack of output encoding in the WP Customer Reviews WordPress plugin, versions before 3.4.3, lead to multiple Stored Cross-Site Scripting vulnerabilities allowing remote attackers to inject arbitrary JavaScript code or HTML.
Credit: contact@wpscan.com
Affected Software | Affected Version | How to fix |
---|---|---|
WP Customer Reviews | <3.4.3 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2021-24135 is a vulnerability in the WP Customer Reviews WordPress plugin that allows remote attackers to inject arbitrary JavaScript code or HTML.
CVE-2021-24135 has a severity value of 6.1, which is considered medium.
Versions of the WP Customer Reviews plugin before 3.4.3 are affected by CVE-2021-24135.
CVE-2021-24135 is classified under CWE-79, which is for Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting').
To fix CVE-2021-24135, update the WP Customer Reviews plugin to version 3.4.3 or later.