First published: Mon Oct 04 2021(Updated: )
The User Registration WordPress plugin before 2.0.2 does not properly sanitise the user_registration_profile_pic_url value when submitted directly via the user_registration_update_profile_details AJAX action. This could allow any authenticated user, such as subscriber, to perform Stored Cross-Site attacks when their profile is viewed
Credit: contact@wpscan.com
Affected Software | Affected Version | How to fix |
---|---|---|
WPEverest User Registration | <2.0.2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2021-24654 is a vulnerability in the User Registration WordPress plugin before version 2.0.2 that allows an authenticated user to perform Stored Cross-Site Scripting (XSS) attacks.
CVE-2021-24654 allows any authenticated user, such as a subscriber, to inject malicious scripts into the user_registration_profile_pic_url value, leading to potential XSS attacks in WordPress.
CVE-2021-24654 has a severity rating of 5.4, which is classified as medium.
To fix CVE-2021-24654, it is recommended to update the User Registration WordPress plugin to version 2.0.2 or newer.
More information about CVE-2021-24654 can be found at the following reference: https://wpscan.com/vulnerability/5c7a9473-d32e-47d6-9f8e-15b96fe758f2