CVE-2021-24180: Related Posts for WordPress < 2.0.4 - Authenticated Reflected Cross-Site Scripting (XSS)
Unvalidated input and lack of output encoding within the Related Posts for WordPress plugin before 2.0.4 lead to a Reflected Cross-Site Scripting (XSS) vulnerability within the 'lang' GET parameter while editing a post, triggered when users with the capability of editing posts access a malicious URL.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2021-24180?
CVE-2021-24180 is a vulnerability in the Related Posts for WordPress plugin before version 2.0.4 that leads to a Reflected Cross-Site Scripting (XSS) attack.
How does CVE-2021-24180 affect WordPress?
CVE-2021-24180 affects WordPress through the Related Posts plugin before version 2.0.4, allowing an attacker to execute cross-site scripting attacks.
What is the severity of CVE-2021-24180?
The severity of CVE-2021-24180 is medium with a CVSS score of 5.4.
How can I fix CVE-2021-24180?
To fix CVE-2021-24180, update the Related Posts plugin for WordPress to version 2.0.4 or above.
Where can I find more information about CVE-2021-24180?
More information about CVE-2021-24180 can be found at the following reference: https://wpscan.com/vulnerability/7593d5c8-cbc2-4469-b36b-5d4fb6d49718