CVE-2021-24576: Easy Accordion < 2.0.22 - Authenticated Stored XSS
Published Oct 11, 2021
·Updated
The Easy Accordion WordPress plugin before 2.0.22 does not properly sanitize inputs when adding new items to an accordion.
Affected Software
1 affected component
Techearty Easy Accordion Wordpress<2.0.22
Event History
Oct 11, 2021
CVE Published
via MITRE·10:45 AM
Data Sourced
via MITRE·10:45 AM
DescriptionWeakness
Frequently Asked Questions
1
What is CVE-2021-24576?
CVE-2021-24576 is a vulnerability in the Easy Accordion WordPress plugin before version 2.0.22 that allows for improper sanitization of inputs when adding new items to an accordion.
2
How does CVE-2021-24576 affect the Easy Accordion plugin?
CVE-2021-24576 affects the Easy Accordion WordPress plugin before version 2.0.22.
3
What is the severity of CVE-2021-24576?
CVE-2021-24576 has a severity rating of 5.4 (medium).
4
What is the CWE category for CVE-2021-24576?
CVE-2021-24576 belongs to CWE category 79 (Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')).
5
Is there a fix for CVE-2021-24576?
Yes, the fix for CVE-2021-24576 is to update the Easy Accordion WordPress plugin to version 2.0.22 or later.