CVE-2021-24332: Autoptimize < 2.8.4 - Authenticated Stored Cross-Site Scripting (XSS)
Published May 24, 2021
·Updated
The Autoptimize WordPress plugin before 2.8.4 was missing proper escaping and sanitisation in some of its settings, allowing high privilege users to set XSS payloads in them, leading to stored Cross-Site Scripting issues
Affected Software
1 affected component
Autoptimize Autoptimize Wordpress<2.8.4
Event History
May 24, 2021
CVE Published
via MITRE·10:58 AM
Data Sourced
via MITRE·10:58 AM
DescriptionWeakness
Frequently Asked Questions
1
What is the severity of CVE-2021-24332?
CVE-2021-24332 has a medium severity rating due to the potential for stored Cross-Site Scripting vulnerabilities.
2
Who is affected by CVE-2021-24332?
CVE-2021-24332 affects users of the Autoptimize WordPress plugin versions prior to 2.8.4.
3
How do I fix CVE-2021-24332?
To fix CVE-2021-24332, update the Autoptimize WordPress plugin to version 2.8.4 or later.
4
What are the consequences of CVE-2021-24332?
The consequences of CVE-2021-24332 include the potential for high privilege users to inject malicious JavaScript through plugin settings.
5
What versions of Autoptimize are safe from CVE-2021-24332?
Versions of Autoptimize that are 2.8.4 and above are safe from CVE-2021-24332.