CVE-2021-24577: Coming Soon and Maintenance Mode < 3.5.3 - Authenticated Stored XSS
The Coming soon and Maintenance mode WordPress plugin before 3.5.3 does not properly sanitize inputs submitted by authenticated users when setting adding or modifying coming soon or maintenance mode pages, leading to stored XSS.
Affected Software
Event History
Frequently Asked Questions
What is the vulnerability ID of this issue?
The vulnerability ID of this issue is CVE-2021-24577.
What is the severity level of CVE-2021-24577?
The severity level of CVE-2021-24577 is medium.
What is the affected software of CVE-2021-24577?
The affected software of CVE-2021-24577 is the Coming soon and Maintenance mode WordPress plugin before version 3.5.3.
What is the vulnerability description for CVE-2021-24577?
CVE-2021-24577 is a vulnerability in the Coming soon and Maintenance mode WordPress plugin before version 3.5.3 that allows authenticated users to submit unproperly sanitized inputs, leading to stored cross-site scripting (XSS).
Is there a fix available for CVE-2021-24577?
Yes, updating the Coming soon and Maintenance mode WordPress plugin to version 3.5.3 or newer fixes CVE-2021-24577.