CVE-2021-24601: WPFront Notification Bar < 2.1.0.08087 - Authenticated Stored XSS
Published Sep 6, 2021
·Updated
The WPFront Notification Bar WordPress plugin before 2.1.0.08087 does not properly sanitise and escape its settings, which could allow high privilege users to perform Cross-Site Scripting attacks even when the unfilteredhtml capability is disallowed.
Affected Software
1 affected component
WPFront WPFront Notification Bar WordPress<2.1.0
Event History
Sep 6, 2021
CVE Published
via MITRE·11:09 AM
Data Sourced
via MITRE·11:09 AM
DescriptionWeakness
Frequently Asked Questions
1
What is CVE-2021-24601?
CVE-2021-24601 is a vulnerability in the WPFront Notification Bar WordPress plugin that allows high privilege users to perform Cross-Site Scripting attacks.
2
How severe is CVE-2021-24601?
The severity of CVE-2021-24601 is rated as medium with a CVSS score of 5.4.
3
What can the vulnerability CVE-2021-24601 allow?
The vulnerability CVE-2021-24601 can allow high privilege users to perform Cross-Site Scripting attacks.