CVE-2021-24613: Post Views Counter < 1.3.5 - Authenticated Stored XSS
Published Sep 20, 2021
·Updated
The Post Views Counter WordPress plugin before 1.3.5 does not sanitise or escape its Post Views Label settings, which could allow high privilege users to perform Cross-Site Scripting attacks in the frontend even when the unfilteredhtml capability is disallowed
Affected Software
1 affected component
dFactory Post Views Counter Wordpress<1.3.5
Event History
Sep 20, 2021
CVE Published
via MITRE·10:06 AM
Data Sourced
via MITRE·10:06 AM
DescriptionWeakness
Frequently Asked Questions
1
What is the severity of CVE-2021-24613?
CVE-2021-24613 is classified as a medium severity vulnerability.
2
What type of vulnerability is CVE-2021-24613?
CVE-2021-24613 is a Cross-Site Scripting (XSS) vulnerability.
3
Who is affected by CVE-2021-24613?
CVE-2021-24613 affects users of the Post Views Counter WordPress plugin versions prior to 1.3.5.
4
How do I fix CVE-2021-24613?
To fix CVE-2021-24613, update the Post Views Counter plugin to version 1.3.5 or later.
5
What can attackers do with CVE-2021-24613?
Attackers can exploit CVE-2021-24613 to perform Cross-Site Scripting attacks on the frontend of WordPress sites.