CVE-2021-24488: Post Grid < 2.1.8 - Reflected Cross-Site Scripting (XSS)
Published Aug 2, 2021
·Updated
The slider import search feature and tab parameter of the Post Grid WordPress plugin before 2.1.8 settings are not properly sanitised before being output back in the pages, leading to Reflected Cross-Site Scripting issues
Affected Software
1 affected component
PickPlugins Post Grid Wordpress<2.1.8
Event History
Aug 2, 2021
CVE Published
via MITRE·10:32 AM
Data Sourced
via MITRE·10:32 AM
DescriptionWeakness
Frequently Asked Questions
1
What is the vulnerability ID?
The vulnerability ID is CVE-2021-24488.
2
What is the affected software?
The affected software is the Post Grid WordPress plugin before version 2.1.8.
3
What is the severity of CVE-2021-24488?
The severity of CVE-2021-24488 is medium (6.1).
4
What are the consequences of CVE-2021-24488?
CVE-2021-24488 can lead to Reflected Cross-Site Scripting issues.
5
How can I fix CVE-2021-24488?
To fix CVE-2021-24488, you should update the Post Grid WordPress plugin to version 2.1.8 or later.