CVE-2021-24342: JNews < 8.0.6 - Reflected Cross-Site Scripting (XSS)
The JNews WordPress theme before 8.0.6 did not sanitise the catid parameter in the POST request /?ajax-request=jnews (with action=jnewsbuildmegacategory), leading to a Reflected Cross-Site Scripting (XSS) issue.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2021-24342?
CVE-2021-24342 is classified as a medium severity vulnerability due to its potential for reflected Cross-Site Scripting (XSS).
How do I fix CVE-2021-24342?
To fix CVE-2021-24342, update the JNews WordPress theme to version 8.0.6 or later, where the cat_id parameter is properly sanitized.
What type of vulnerability is CVE-2021-24342?
CVE-2021-24342 is a reflected Cross-Site Scripting (XSS) vulnerability affecting the JNews WordPress theme.
What are the potential impacts of CVE-2021-24342?
The potential impacts of CVE-2021-24342 include unauthorized script execution and potential data theft due to XSS exploitation.
Who is affected by CVE-2021-24342?
Users of the JNews WordPress theme prior to version 8.0.6 are affected by CVE-2021-24342.