CVE-2021-24812: BetterLinks < 1.2.6 - Admin+ Stored Cross-Site Scripting
Published Nov 23, 2021
·Updated
The BetterLinks WordPress plugin before 1.2.6 does not sanitise and escape some of imported link fields, which could lead to Stored Cross-Site Scripting issues when an admin import a malicious CSV.
Affected Software
1 affected component
WPDeveloper Betterlinks Wordpress<1.2.6
Event History
Nov 23, 2021
CVE Published
via MITRE·07:16 PM
Data Sourced
via MITRE·07:16 PM
DescriptionWeakness
Frequently Asked Questions
1
What is the vulnerability ID for the BetterLinks WordPress plugin?
The vulnerability ID for the BetterLinks WordPress plugin is CVE-2021-24812.
2
What is the severity of CVE-2021-24812?
The severity of CVE-2021-24812 is medium with a severity value of 5.4.
3
What is the affected software for CVE-2021-24812?
The affected software for CVE-2021-24812 is the BetterLinks WordPress plugin version up to exclusive 1.2.6.
4
What is the CWE number associated with CVE-2021-24812?
The CWE number associated with CVE-2021-24812 is 79.
5
How can I fix CVE-2021-24812?
To fix CVE-2021-24812, update the BetterLinks WordPress plugin to version 1.2.6 or higher.