CVE-2021-24648: Registration Magic < 5.0.1.9 - Reflected Cross-Site Scripting
The RegistrationMagic WordPress plugin before 5.0.1.9 does not sanitise and escape the rmsearchvalue parameter before outputting back in an attribute, leading to a Reflected Cross-Site Scripting
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is CVE-2021-24648?
CVE-2021-24648 is a vulnerability in the RegistrationMagic WordPress plugin before version 5.0.1.9 that allows for Reflected Cross-Site Scripting attacks.
How does CVE-2021-24648 impact WordPress sites?
CVE-2021-24648 allows an attacker to execute malicious scripts on a WordPress site by exploiting the vulnerability in the RegistrationMagic plugin.
What is the severity of CVE-2021-24648?
CVE-2021-24648 has a severity score of 6.1, which is considered medium.
How do I fix CVE-2021-24648?
To fix CVE-2021-24648, update the RegistrationMagic WordPress plugin to version 5.0.1.9 or higher.
Is there any additional information about CVE-2021-24648?
For more information about CVE-2021-24648, you can refer to the official changeset on the WordPress plugin repository or the vulnerability report on WPScan.