First published: Mon Apr 05 2021(Updated: )
The WordPress Related Posts plugin through 3.6.4 contains an authenticated (admin+) stored XSS vulnerability in the title field on the settings page. By exploiting that an attacker will be able to execute JavaScript code in the user's browser.
Credit: contact@wpscan.com
Affected Software | Affected Version | How to fix |
---|---|---|
Wphive Wordpress Related Posts | <=3.6.4 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID for this vulnerability is CVE-2021-24211.
CVE-2021-24211 has a severity rating of 5.4 (medium).
The WordPress Related Posts plugin version 3.6.4 is affected by CVE-2021-24211.
An attacker can execute JavaScript code in the user's browser by exploiting CVE-2021-24211.
Updating to a version that is not affected by CVE-2021-24211, such as a patched version, can fix the vulnerability.