CVE-2021-24286: Redirect 404 to Parent < 1.3.1 - Reflected Cross-Site Scripting (XSS)
The settings page of the Redirect 404 to parent WordPress plugin before 1.3.1 did not properly sanitise the tab parameter before outputting it back, leading to a reflected Cross-Site Scripting issue
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2021-24286?
The severity of CVE-2021-24286 is medium (6.1).
How does CVE-2021-24286 affect the Redirect 404 to parent WordPress plugin?
CVE-2021-24286 affects the Redirect 404 to parent WordPress plugin version up to (exclusive) 1.3.1.
What is the vulnerability in CVE-2021-24286?
The vulnerability in CVE-2021-24286 is a reflected Cross-Site Scripting (XSS) issue.
Is there a fix available for CVE-2021-24286?
Yes, the fix for CVE-2021-24286 is to upgrade to version 1.3.1 or above of the Redirect 404 to parent WordPress plugin.
Where can I find more information about CVE-2021-24286?
You can find more information about CVE-2021-24286 at the following references: [Link 1](http://packetstormsecurity.com/files/164328/WordPress-Redirect-404-To-Parent-1.3.0-Cross-Site-Scripting.html) and [Link 2](https://wpscan.com/vulnerability/b9a535f3-cb0b-46fe-b345-da3462584e27).