First published: Mon Jun 21 2021(Updated: )
The Pods – Custom Content Types and Fields WordPress plugin before 2.7.27 was vulnerable to an Authenticated Stored Cross-Site Scripting (XSS) security vulnerability within the 'Singular Label' field parameter.
Credit: contact@wpscan.com
Affected Software | Affected Version | How to fix |
---|---|---|
Pods Foundation | <2.7.27 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2021-24338 has a medium severity rating due to the authentication requirement for exploitation.
To remediate CVE-2021-24338, update the Pods – Custom Content Types and Fields WordPress plugin to version 2.7.27 or later.
Users of the Pods – Custom Content Types and Fields WordPress plugin versions prior to 2.7.27 are affected by CVE-2021-24338.
CVE-2021-24338 is an Authenticated Stored Cross-Site Scripting (XSS) vulnerability.
CVE-2021-24338 can allow authenticated attackers to inject malicious scripts that could lead to account takeover or data exposure.