CVE-2021-24808: BP Better Messages < 1.9.9.41 - Reflected Cross-Site Scripting
Published Nov 1, 2021
·Updated
The BP Better Messages WordPress plugin before 1.9.9.41 sanitise (with sanitizetextfield) but does not escape the 'subject' parameter before outputting it back in an attribute, leading to a Reflected Cross-Site Scripting issue
Affected Software
1 affected component
WordPlus Better Messages Wordpress<1.9.9.41
Remediation
Event History
Nov 1, 2021
CVE Published
via MITRE·08:46 AM
Data Sourced
via MITRE·08:46 AM
DescriptionWeakness
Frequently Asked Questions
1
What is the severity of CVE-2021-24808?
CVE-2021-24808 is classified as a medium severity vulnerability due to its potential to lead to Reflected Cross-Site Scripting attacks.
2
How do I fix CVE-2021-24808?
To fix CVE-2021-24808, update the BP Better Messages WordPress plugin to version 1.9.9.41 or later.
3
What type of vulnerability is CVE-2021-24808?
CVE-2021-24808 is a Reflected Cross-Site Scripting (XSS) vulnerability.
4
What parameters are affected by CVE-2021-24808?
CVE-2021-24808 specifically affects the 'subject' parameter in the BP Better Messages plugin.
5
Who is affected by CVE-2021-24808?
Any WordPress site using the BP Better Messages plugin before version 1.9.9.41 is affected by CVE-2021-24808.