CVE-2021-24734: Compact WP Audio Player < 1.9.7 - Contributor+ Stored Cross-Site Scripting
Published Oct 18, 2021
·Updated
The Compact WP Audio Player WordPress plugin before 1.9.7 does not escape some of its shortcodes attributes, which could allow users with a role as low as Contributor to perform Stored Cross-Site Scripting attacks.
Affected Software
1 affected component
Tipsandtricks-hq Compact Wp Audio Player Wordpress<1.9.7
Event History
Oct 18, 2021
CVE Published
via MITRE·01:46 PM
Data Sourced
via MITRE·01:46 PM
DescriptionWeakness
Frequently Asked Questions
1
What is the vulnerability ID for the Compact WP Audio Player plugin?
The vulnerability ID for the Compact WP Audio Player plugin is CVE-2021-24734.
2
What is the severity of CVE-2021-24734?
CVE-2021-24734 has a severity value of 5.4 (medium).
3
What is the affected software of CVE-2021-24734?
The affected software of CVE-2021-24734 is the Compact WP Audio Player plugin before version 1.9.7.
4
What is the description of CVE-2021-24734?
CVE-2021-24734 is a vulnerability in the Compact WP Audio Player plugin that allows users with a role as low as Contributor to perform Stored Cross-Site Scripting attacks.
5
How can I fix CVE-2021-24734?
To fix CVE-2021-24734, update the Compact WP Audio Player plugin to version 1.9.7 or later.