First published: Mon Oct 11 2021(Updated: )
The Weather Effect WordPress plugin before 1.3.4 does not have any CSRF checks in place when saving its settings, and do not validate or escape them, which could lead to Stored Cross-Site Scripting issue.
Credit: contact@wpscan.com
Affected Software | Affected Version | How to fix |
---|---|---|
Awplife Weather Effect | <1.3.4 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2021-24683 is a vulnerability in the Weather Effect WordPress plugin before version 1.3.4 that allows for stored cross-site scripting (XSS) attacks due to the lack of CSRF checks and improper validation and escaping of settings.
The severity of CVE-2021-24683 is medium, with a CVSS score of 5.4.
CVE-2021-24683 affects the Weather Effect WordPress plugin before version 1.3.4 by not implementing CSRF checks and not properly validating or escaping settings, which can lead to stored cross-site scripting (XSS) attacks.
To fix CVE-2021-24683, update the Weather Effect WordPress plugin to version 1.3.4 or later, which includes CSRF checks and proper validation and escaping of settings.
You can find more information about CVE-2021-24683 at the following reference: [CVE-2021-24683](https://wpscan.com/vulnerability/54f95b51-5804-4bee-9e4a-f73b8ef9bbd5)