CVE-2021-24364: Jannah < 5.4.4 - Reflected Cross-Site Scripting (XSS)
Published Jun 21, 2021
·Updated
The Jannah WordPress theme before 5.4.4 did not properly sanitize the options JSON parameter in its tiegetuserweather AJAX action before outputting it back in the page, leading to a Reflected Cross-Site Scripting (XSS) vulnerability.
Affected Software
1 affected component
Tielabs Jannah Wordpress<5.4.4
Event History
Jun 21, 2021
CVE Published
via MITRE·07:18 PM
Data Sourced
via MITRE·07:18 PM
DescriptionWeakness
Frequently Asked Questions
1
What is the severity of CVE-2021-24364?
CVE-2021-24364 is classified as a high-severity vulnerability due to its potential for exploitation through Reflected Cross-Site Scripting.
2
How do I fix CVE-2021-24364?
To mitigate CVE-2021-24364, update the Jannah WordPress theme to version 5.4.4 or later.
3
Who is affected by CVE-2021-24364?
CVE-2021-24364 affects users of the Jannah WordPress theme versions prior to 5.4.4.
4
What type of vulnerability is CVE-2021-24364?
CVE-2021-24364 is a Reflected Cross-Site Scripting (XSS) vulnerability.
5
When was CVE-2021-24364 disclosed?
CVE-2021-24364 was disclosed prior to the release of the patch in version 5.4.4 of the Jannah WordPress theme.