CVE-2021-24283: Accordion < 2.2.30 - Authenticated Reflected Cross-Site Scripting (XSS)
Published May 14, 2021
·Updated
The tab GET parameter of the settings page is not sanitised or escaped when being output back in an HTML attribute, leading to a reflected XSS issue.
Affected Software
1 affected component
PickPlugins Accordion Wordpress<2.2.30
Event History
May 14, 2021
CVE Published
via MITRE·11:38 AM
Data Sourced
via MITRE·11:38 AM
DescriptionWeakness
Frequently Asked Questions
1
What is CVE-2021-24283?
CVE-2021-24283 is a vulnerability that allows for a reflected XSS attack in Pickplugins Accordion plugin for WordPress.
2
How severe is CVE-2021-24283?
CVE-2021-24283 has a severity level of medium with a CVSS score of 5.4.
3
What software is affected by CVE-2021-24283?
The Pickplugins Accordion plugin for WordPress, up to version 2.2.30, is affected by CVE-2021-24283.
4
What is the Common Weakness Enumeration (CWE) for CVE-2021-24283?
The CWE for CVE-2021-24283 is CWE-79, which is Cross-Site Scripting (XSS).
5
How can I fix CVE-2021-24283?
To fix CVE-2021-24283, update the Pickplugins Accordion plugin to a version beyond 2.2.30 or apply any official patches or fixes provided by the plugin vendor.