CVE-2021-24412: Html5 Audio Player < 2.1.3 - Contributor+ Stored Cross-Site Scripting
The Html5 Audio Player – Audio Player for WordPress plugin before 2.1.3 does not sanitise or validate the parameters from its shortcode, allowing users with a role as low as contributor to set Cross-Site Scripting payload in them which will be triggered in the page/s with the embed malicious shortcode
Other sources
The Html5 Audio Player – Audio Player for WordPress plugin before 2.1.3 does not sanitise or validate the parameters from its shortcode, allowing users with a role as low as contributor to set Cross-Site Scripting payload in them which will be triggered in the page/s with the embed malicious shortcode
Affected Software
Event History
Frequently Asked Questions
What is the vulnerability ID for this vulnerability?
The vulnerability ID for this vulnerability is CVE-2021-24412.
What is the severity of CVE-2021-24412?
The severity of CVE-2021-24412 is medium with a severity value of 5.4.
Which software is affected by CVE-2021-24412?
The Html5 Audio Player - Audio Player for WordPress plugin before version 2.1.3 is affected by CVE-2021-24412.
What is the impact of CVE-2021-24412?
CVE-2021-24412 allows users with low-level roles, such as contributors, to set Cross-Site Scripting (XSS) payloads in the plugin's parameters, which can be triggered on affected pages.
How can I fix CVE-2021-24412?
To fix CVE-2021-24412, update the Html5 Audio Player - Audio Player for WordPress plugin to version 2.1.3 or later.