First published: Mon Oct 11 2021(Updated: )
The GeoDirectory Business Directory WordPress plugin before 2.1.1.3 was vulnerable to Authenticated Stored Cross-Site Scripting (XSS).
Credit: contact@wpscan.com
Affected Software | Affected Version | How to fix |
---|---|---|
AyeCode GeoDirectory | <2.1.1.3 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2021-24720 is a vulnerability in the GeoDirectory Business Directory WordPress plugin before version 2.1.1.3 that allows for Authenticated Stored Cross-Site Scripting (XSS).
CVE-2021-24720 has a severity rating of 5.4 (medium).
CVE-2021-24720 affects the GeoDirectory plugin before version 2.1.1.3.
The CWE ID for CVE-2021-24720 is CWE-79.
You can find more information about CVE-2021-24720 at the following references: [Link 1](https://github.com/BigTiger2020/word-press/blob/main/WrodPress%20Plugin%20GeoDirectory%E2%80%94%E2%80%94Stored%20Cross-Site%20Scripting%20.md), [Link 2](https://plugins.trac.wordpress.org/changeset/2596452/geodirectory), [Link 3](https://wpscan.com/vulnerability/9de5cc51-f64c-4475-a0f4-d932dc4364a6).