First published: Mon Aug 02 2021(Updated: )
The slider import search feature and tab parameter of the Post Grid WordPress plugin before 2.1.8 settings are not properly sanitised before being output back in the pages, leading to Reflected Cross-Site Scripting issues
Credit: contact@wpscan.com
Affected Software | Affected Version | How to fix |
---|---|---|
PickPlugins Post Grid | <2.1.8 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID is CVE-2021-24488.
The affected software is the Post Grid WordPress plugin before version 2.1.8.
The severity of CVE-2021-24488 is medium (6.1).
CVE-2021-24488 can lead to Reflected Cross-Site Scripting issues.
To fix CVE-2021-24488, you should update the Post Grid WordPress plugin to version 2.1.8 or later.