CVE-2021-24588: SMS Alert Order Notifications – WooCommerce < 3.4.7 Authenticated Cross Site Scripting
Published Sep 6, 2021
·Updated
The SMS Alert Order Notifications WordPress plugin before 3.4.7 is affected by a cross site scripting (XSS) vulnerability in the plugin's setting page.
Affected Software
1 affected component
Cozyvision Sms Alert Order Notifications Wordpress<3.4.7
Event History
Sep 6, 2021
CVE Published
via MITRE·11:09 AM
Data Sourced
via MITRE·11:09 AM
DescriptionWeakness
Frequently Asked Questions
1
What is the severity of CVE-2021-24588?
CVE-2021-24588 is considered a medium severity vulnerability due to its cross-site scripting (XSS) nature.
2
How do I fix CVE-2021-24588?
To fix CVE-2021-24588, update the SMS Alert Order Notifications plugin to version 3.4.7 or later.
3
Who is affected by CVE-2021-24588?
Any WordPress site utilizing the SMS Alert Order Notifications plugin versions below 3.4.7 is affected by CVE-2021-24588.
4
What type of vulnerability is CVE-2021-24588?
CVE-2021-24588 is a cross-site scripting (XSS) vulnerability affecting the plugin's settings page.
5
When was CVE-2021-24588 published?
CVE-2021-24588 was published in early 2021 and is relevant to specific older versions of the plugin.