CVE-2021-24512: Video Posts Webcam Recorder < 3.2.4 - Authenticated Reflected XSS
Published Aug 16, 2021
·Updated
The Video Posts Webcam Recorder WordPress plugin before 3.2.4 has an authenticated reflected cross site scripting (XSS) vulnerability in one of the administrative functions for handling deletion of videos.
Affected Software
1 affected component
VideoWhisper Video Posts Webcam Recorder Wordpress<3.2.4
Event History
Aug 16, 2021
CVE Published
via MITRE·10:48 AM
Data Sourced
via MITRE·10:48 AM
DescriptionWeakness
Frequently Asked Questions
1
What is the severity of CVE-2021-24512?
CVE-2021-24512 has a medium severity rating due to the potential for exploitation through cross-site scripting.
2
How do I fix CVE-2021-24512?
To fix CVE-2021-24512, update the Video Posts Webcam Recorder plugin to version 3.2.4 or later.
3
What type of vulnerability is CVE-2021-24512?
CVE-2021-24512 is an authenticated reflected cross-site scripting (XSS) vulnerability.
4
Who is affected by CVE-2021-24512?
Users of the Video Posts Webcam Recorder WordPress plugin versions prior to 3.2.4 are affected by CVE-2021-24512.
5
What can attackers do with CVE-2021-24512?
Attackers can exploit CVE-2021-24512 to execute malicious scripts in the context of an authenticated user's browser.