First published: Mon Jun 14 2021(Updated: )
The Visitors WordPress plugin through 0.3 is affected by an Unauthenticated Stored Cross-Site Scripting (XSS) vulnerability. The plugin would display the user's user agent string without validation or encoding within the WordPress admin panel.
Credit: contact@wpscan.com
Affected Software | Affected Version | How to fix |
---|---|---|
Bestwebsoft Visitors Online Wordpress | <=0.3 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2021-24350 is an Unauthenticated Stored Cross-Site Scripting (XSS) vulnerability in the Visitors WordPress plugin through version 0.3.
CVE-2021-24350 allows an attacker to execute malicious JavaScript code in the user's browser, potentially leading to unauthorized actions or data theft.
The severity of CVE-2021-24350 is medium, with a CVSS score of 6.1.
To mitigate the impact of CVE-2021-24350, update the Visitors WordPress plugin to a version higher than 0.3.
You can find more information about CVE-2021-24350 at the following reference link: https://wpscan.com/vulnerability/06f1889d-8e2f-481a-b91b-3a8008e00ffc