CVE-2021-24250: Business Directory Plugin < 5.11.2 - Authenticated Stored Cross-Site Scripting
The Business Directory Plugin – Easy Listing Directories for WordPress WordPress plugin before 5.11.2 suffered from lack of sanitisation in the label of the Form Fields, leading to Authenticated Stored Cross-Site Scripting issues across various pages of the plugin.
Other sources
The Business Directory Plugin – Easy Listing Directories for WordPress WordPress plugin before 5.11.2 suffered from lack of sanitisation in the label of the Form Fields, leading to Authenticated Stored Cross-Site Scripting issues across various pages of the plugin.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2021-24250?
CVE-2021-24250 has been classified with a high severity due to its potential for exploited stored cross-site scripting attacks.
How do I fix CVE-2021-24250?
To resolve CVE-2021-24250, update the Business Directory Plugin to version 5.11.2 or later.
What is the vulnerability type of CVE-2021-24250?
CVE-2021-24250 is classified as an Authenticated Stored Cross-Site Scripting vulnerability.
Who is affected by CVE-2021-24250?
Users of the Business Directory Plugin for WordPress prior to version 5.11.2 are affected by CVE-2021-24250.
What impact does CVE-2021-24250 have?
CVE-2021-24250 can lead to unauthorized scripts being executed in the context of the user's browser, potentially compromising user data.