First published: Tue Feb 01 2022(Updated: )
The RegistrationMagic WordPress plugin before 5.0.1.9 does not sanitise and escape the rm_search_value parameter before outputting back in an attribute, leading to a Reflected Cross-Site Scripting
Credit: contact@wpscan.com
Affected Software | Affected Version | How to fix |
---|---|---|
Metagauss Registrationmagic | <5.0.1.9 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2021-24648 is a vulnerability in the RegistrationMagic WordPress plugin before version 5.0.1.9 that allows for Reflected Cross-Site Scripting attacks.
CVE-2021-24648 allows an attacker to execute malicious scripts on a WordPress site by exploiting the vulnerability in the RegistrationMagic plugin.
CVE-2021-24648 has a severity score of 6.1, which is considered medium.
To fix CVE-2021-24648, update the RegistrationMagic WordPress plugin to version 5.0.1.9 or higher.
For more information about CVE-2021-24648, you can refer to the official changeset on the WordPress plugin repository or the vulnerability report on WPScan.