CVE-2021-24389: FoodBakery < 2.2 - Reflected Cross-Site Scripting (XSS)
The WP Foodbakery WordPress plugin before 2.2, used in the FoodBakery WordPress theme before 2.2 did not properly sanitize the foodbakeryradius parameter before outputting it back in the response, leading to an unauthenticated Reflected Cross-Site Scripting (XSS) vulnerability.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2021-24389?
CVE-2021-24389 is rated as a medium severity vulnerability due to its potential to allow XSS attacks.
How do I fix CVE-2021-24389?
To fix CVE-2021-24389, you should update the WP Foodbakery plugin to version 2.2 or higher.
What type of vulnerability is CVE-2021-24389?
CVE-2021-24389 is an unauthenticated Reflected Cross-Site Scripting (XSS) vulnerability.
Who is affected by CVE-2021-24389?
CVE-2021-24389 affects users of the WP Foodbakery WordPress plugin and FoodBakery WordPress theme prior to version 2.2.
Is CVE-2021-24389 exploitable without authentication?
Yes, CVE-2021-24389 can be exploited without authentication, making it particularly dangerous.