CVE-2021-24425: myStickymenu < 2.5.2 - Authenticated Stored XSS
The Floating Notification Bar, Sticky Menu on Scroll, and Sticky Header for Any Theme – myStickymenu WordPress plugin before 2.5.2 does not sanitise or escape its Bar Text settings, allowing hight privilege users to use malicious JavaScript in it, leading to a Stored Cross-Site Scripting issue, which will be triggered in the plugin's setting, as well as all front-page of the blog (when the Welcome bar is active)
Other sources
The Floating Notification Bar, Sticky Menu on Scroll, and Sticky Header for Any Theme – myStickymenu WordPress plugin before 2.5.2 does not sanitise or escape its Bar Text settings, allowing hight privilege users to use malicious JavaScript in it, leading to a Stored Cross-Site Scripting issue, which will be triggered in the plugin's setting, as well as all front-page of the blog (when the Welcome bar is active)
Affected Software
Event History
Frequently Asked Questions
What is CVE-2021-24425?
CVE-2021-24425 refers to a vulnerability in the Floating Notification Bar, Sticky Menu on Scroll, and Sticky Header for Any Theme – myStickymenu WordPress plugin before version 2.5.2.
What is the severity of CVE-2021-24425?
The severity of CVE-2021-24425 is medium with a CVSS score of 4.8.
What is the affected software of CVE-2021-24425?
The affected software is the myStickymenu WordPress plugin before version 2.5.2.
What is the CWE classification of CVE-2021-24425?
CVE-2021-24425 is classified as CWE-79, which is a Cross-Site Scripting vulnerability.
How can I fix CVE-2021-24425?
To fix CVE-2021-24425, update the myStickymenu WordPress plugin to version 2.5.2 or higher.