CVE-2021-24564: WPFront Scroll Top < 2.0.6.07225 - Authenticated Stored XSS
The WPFront Scroll Top WordPress plugin before 2.0.6.07225 does not sanitise or escape its Image ALT setting before outputting it attributes, leading to an Authenticated Stored Cross-Site Scripting issues even when the unfilteredhtml capability is disallowed.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2021-24564?
CVE-2021-24564 has a medium severity rating due to its potential for Authenticated Stored Cross-Site Scripting vulnerabilities.
How do I fix CVE-2021-24564?
To fix CVE-2021-24564, update the WPFront Scroll Top WordPress plugin to version 2.0.6.07225 or later.
Who is affected by CVE-2021-24564?
CVE-2021-24564 affects all versions of the WPFront Scroll Top plugin prior to 2.0.6.07225 available for WordPress.
What type of vulnerability is CVE-2021-24564?
CVE-2021-24564 is classified as an Authenticated Stored Cross-Site Scripting vulnerability.
Can CVE-2021-24564 be exploited without authentication?
No, CVE-2021-24564 requires authenticated access to exploit the vulnerability.