CVE-2021-24722: Restaurant Menu by MotoPress < 2.4.2 - Admin+ Stored Cross Site Scripting
Published Nov 1, 2021
·Updated
The Restaurant Menu by MotoPress WordPress plugin before 2.4.2 does not properly sanitize or escape inputs when creating new menu items, which could allow high privilege users to perform Cross-Site Scripting attacks even when the unfilteredhtml capability is disallowed
Affected Software
1 affected component
MotoPress Restaurant Menu Wordpress<2.4.2
Event History
Nov 1, 2021
CVE Published
via MITRE·08:46 AM
Data Sourced
via MITRE·08:46 AM
DescriptionWeakness
Frequently Asked Questions
1
What is the vulnerability ID for this vulnerability?
CVE-2021-24722
2
What is the severity of CVE-2021-24722?
The severity of CVE-2021-24722 is medium (4.8).
3
How does CVE-2021-24722 affect the MotoPress Restaurant Menu plugin?
CVE-2021-24722 affects the MotoPress Restaurant Menu plugin before version 2.4.2.
4
What is the impact of CVE-2021-24722?
CVE-2021-24722 allows high privilege users to perform Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed.
5
How can I fix CVE-2021-24722 in the MotoPress Restaurant Menu plugin?
To fix CVE-2021-24722, you should update the MotoPress Restaurant Menu plugin to version 2.4.2 or later.