First published: Thu May 06 2021(Updated: )
The Business Directory Plugin – Easy Listing Directories for WordPress WordPress plugin before 5.11.1 suffered from Cross-Site Request Forgery issues, allowing an attacker to make a logged in administrator add, edit or delete form fields, which could also lead to Stored Cross-Site Scripting issues.
Credit: contact@wpscan.com
Affected Software | Affected Version | How to fix |
---|---|---|
Business Directory Plugin | <5.11.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2021-24178 has a medium severity rating due to the potential for Cross-Site Request Forgery and Stored Cross-Site Scripting vulnerabilities.
To fix CVE-2021-24178, update the Business Directory Plugin - Easy Listing Directories to version 5.11.1 or later.
CVE-2021-24178 is a Cross-Site Request Forgery (CSRF) vulnerability affecting the Business Directory Plugin for WordPress.
Yes, CVE-2021-24178 can potentially lead to Stored Cross-Site Scripting attacks if exploited by an attacker.
Users of the Business Directory Plugin - Easy Listing Directories for WordPress versions prior to 5.11.1 are affected by CVE-2021-24178.