First published: Thu May 06 2021(Updated: )
The Business Directory Plugin – Easy Listing Directories for WordPress WordPress plugin before 5.11.2 suffered from lack of sanitisation in the label of the Form Fields, leading to Authenticated Stored Cross-Site Scripting issues across various pages of the plugin.
Credit: contact@wpscan.com
Affected Software | Affected Version | How to fix |
---|---|---|
Business Directory Plugin | <5.11.2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2021-24250 has been classified with a high severity due to its potential for exploited stored cross-site scripting attacks.
To resolve CVE-2021-24250, update the Business Directory Plugin to version 5.11.2 or later.
CVE-2021-24250 is classified as an Authenticated Stored Cross-Site Scripting vulnerability.
Users of the Business Directory Plugin for WordPress prior to version 5.11.2 are affected by CVE-2021-24250.
CVE-2021-24250 can lead to unauthorized scripts being executed in the context of the user's browser, potentially compromising user data.