CVE-2021-24720: GeoDirectory < 2.1.1.3 - Authenticated Stored Cross-Site Scripting (XSS)
The GeoDirectory Business Directory WordPress plugin before 2.1.1.3 was vulnerable to Authenticated Stored Cross-Site Scripting (XSS).
Affected Software
Remediation
Event History
Frequently Asked Questions
What is CVE-2021-24720?
CVE-2021-24720 is a vulnerability in the GeoDirectory Business Directory WordPress plugin before version 2.1.1.3 that allows for Authenticated Stored Cross-Site Scripting (XSS).
How severe is CVE-2021-24720?
CVE-2021-24720 has a severity rating of 5.4 (medium).
How does CVE-2021-24720 affect the GeoDirectory plugin?
CVE-2021-24720 affects the GeoDirectory plugin before version 2.1.1.3.
What is the Common Weakness Enumeration (CWE) ID for CVE-2021-24720?
The CWE ID for CVE-2021-24720 is CWE-79.
Where can I find more information about CVE-2021-24720?
You can find more information about CVE-2021-24720 at the following references: [Link 1](https://github.com/BigTiger2020/word-press/blob/main/WrodPress%20Plugin%20GeoDirectory%E2%80%94%E2%80%94Stored%20Cross-Site%20Scripting%20.md), [Link 2](https://plugins.trac.wordpress.org/changeset/2596452/geodirectory), [Link 3](https://wpscan.com/vulnerability/9de5cc51-f64c-4475-a0f4-d932dc4364a6).