CVE-2021-24365: Admin Columns Free (< 4.3.2) & Pro (< 5.5.2) - Authenticated Stored Cross-Site Scripting (XSS) in Custom Field
The Admin Columns WordPress plugin Free before 4.3.2 and Pro before 5.5.2 allowed to configure individual columns for tables. Each column had a type. The type "Custom Field" allowed to choose an arbitrary database column to display in the table. There was no escaping applied to the contents of "Custom Field" columns.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2021-24365?
CVE-2021-24365 has a high severity rating due to the potential for SQL injection vulnerabilities.
How do I fix CVE-2021-24365?
To fix CVE-2021-24365, upgrade to Admin Columns Free version 4.3.2 or Pro version 5.5.2 or later.
What are the potential risks of CVE-2021-24365?
The risks of CVE-2021-24365 include unauthorized database access and possible data manipulation through SQL injection.
Which versions of Admin Columns are affected by CVE-2021-24365?
Admin Columns Free versions before 4.3.2 and Pro versions before 5.5.2 are affected by CVE-2021-24365.
Is CVE-2021-24365 specific to WordPress?
Yes, CVE-2021-24365 specifically affects the Admin Columns plugin used in WordPress.