First published: Mon Aug 23 2021(Updated: )
The WPFront Scroll Top WordPress plugin before 2.0.6.07225 does not sanitise or escape its Image ALT setting before outputting it attributes, leading to an Authenticated Stored Cross-Site Scripting issues even when the unfiltered_html capability is disallowed.
Credit: contact@wpscan.com
Affected Software | Affected Version | How to fix |
---|---|---|
WordPress Scroll Top | <2.0.6.07225 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2021-24564 has a medium severity rating due to its potential for Authenticated Stored Cross-Site Scripting vulnerabilities.
To fix CVE-2021-24564, update the WPFront Scroll Top WordPress plugin to version 2.0.6.07225 or later.
CVE-2021-24564 affects all versions of the WPFront Scroll Top plugin prior to 2.0.6.07225 available for WordPress.
CVE-2021-24564 is classified as an Authenticated Stored Cross-Site Scripting vulnerability.
No, CVE-2021-24564 requires authenticated access to exploit the vulnerability.