First published: Fri May 14 2021(Updated: )
The tab GET parameter of the settings page is not sanitised or escaped when being output back in an HTML attribute, leading to a reflected XSS issue.
Credit: contact@wpscan.com
Affected Software | Affected Version | How to fix |
---|---|---|
PickPlugins Accordion | <2.2.30 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2021-24283 is a vulnerability that allows for a reflected XSS attack in Pickplugins Accordion plugin for WordPress.
CVE-2021-24283 has a severity level of medium with a CVSS score of 5.4.
The Pickplugins Accordion plugin for WordPress, up to version 2.2.30, is affected by CVE-2021-24283.
The CWE for CVE-2021-24283 is CWE-79, which is Cross-Site Scripting (XSS).
To fix CVE-2021-24283, update the Pickplugins Accordion plugin to a version beyond 2.2.30 or apply any official patches or fixes provided by the plugin vendor.