CVE-2021-24738: Logo Carousel < 3.4.2 - Contributor+ Stored Cross-Site Scripting
The Logo Carousel WordPress plugin before 3.4.2 does not validate and escape the "Logo Margin" carousel option, which could allow users with a role as low as Contributor to perform Stored Cross-Site Scripting attacks
Affected Software
Event History
Frequently Asked Questions
What is CVE-2021-24738?
CVE-2021-24738 is a vulnerability in the Logo Carousel WordPress plugin before version 3.4.2 that allows users with a role as low as Contributor to perform Stored Cross-Site Scripting attacks.
How severe is CVE-2021-24738?
CVE-2021-24738 has a severity keyword of 'medium' and a severity value of 5.4.
What is the affected software version of CVE-2021-24738?
CVE-2021-24738 affects the Logo Carousel WordPress plugin versions up to and exclusive of 3.4.2.
How can the CVE-2021-24738 vulnerability be exploited?
The CVE-2021-24738 vulnerability can be exploited by using the 'Logo Margin' carousel option and injecting malicious code, allowing for Stored Cross-Site Scripting attacks.
Is there a fix for CVE-2021-24738?
Yes, the fix for CVE-2021-24738 is to update the Logo Carousel WordPress plugin to version 3.4.2 or above.