CVE-2021-24178: Business Directory Plugin < 5.11.1 - Arbitrary Add/Edit/Delete Form Field to Stored XSS
The Business Directory Plugin – Easy Listing Directories for WordPress WordPress plugin before 5.11.1 suffered from Cross-Site Request Forgery issues, allowing an attacker to make a logged in administrator add, edit or delete form fields, which could also lead to Stored Cross-Site Scripting issues.
Other sources
The Business Directory Plugin – Easy Listing Directories for WordPress WordPress plugin before 5.11.1 suffered from Cross-Site Request Forgery issues, allowing an attacker to make a logged in administrator add, edit or delete form fields, which could also lead to Stored Cross-Site Scripting issues.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2021-24178?
CVE-2021-24178 has a medium severity rating due to the potential for Cross-Site Request Forgery and Stored Cross-Site Scripting vulnerabilities.
How do I fix CVE-2021-24178?
To fix CVE-2021-24178, update the Business Directory Plugin - Easy Listing Directories to version 5.11.1 or later.
What type of vulnerability is CVE-2021-24178?
CVE-2021-24178 is a Cross-Site Request Forgery (CSRF) vulnerability affecting the Business Directory Plugin for WordPress.
Can CVE-2021-24178 lead to further attacks?
Yes, CVE-2021-24178 can potentially lead to Stored Cross-Site Scripting attacks if exploited by an attacker.
Who is affected by CVE-2021-24178?
Users of the Business Directory Plugin - Easy Listing Directories for WordPress versions prior to 5.11.1 are affected by CVE-2021-24178.