CVE-2021-24444: TaxoPress < 3.0.7.2 - Authenticated Stored Cross-Site Scripting (XSS)
The TaxoPress – Create and Manage Taxonomies, Tags, Categories WordPress plugin before 3.0.7.2 does not sanitise its Taxonomy description field, allowing high privilege users to set JavaScript payload in them even when the unfilteredhtml capability is disallowed, leading to an authenticated Stored Cross-Site Scripting issue.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2021-24444?
CVE-2021-24444 is classified as a high severity vulnerability due to its potential for allowing cross-site scripting (XSS) attacks.
How do I fix CVE-2021-24444?
To fix CVE-2021-24444, update the TaxoPress plugin to version 3.0.7.2 or later.
Who is affected by CVE-2021-24444?
CVE-2021-24444 affects users of the TaxoPress plugin versions prior to 3.0.7.2.
What kind of attack does CVE-2021-24444 enable?
CVE-2021-24444 enables high privilege users to execute JavaScript payloads via an insecure taxonomy description field.
Is CVE-2021-24444 a client-side or server-side vulnerability?
CVE-2021-24444 is primarily a client-side vulnerability, allowing the execution of JavaScript in the user's browser.