First published: Tue Nov 23 2021(Updated: )
The BetterLinks WordPress plugin before 1.2.6 does not sanitise and escape some of imported link fields, which could lead to Stored Cross-Site Scripting issues when an admin import a malicious CSV.
Credit: contact@wpscan.com
Affected Software | Affected Version | How to fix |
---|---|---|
Wpdeveloper Betterlinks | <1.2.6 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID for the BetterLinks WordPress plugin is CVE-2021-24812.
The severity of CVE-2021-24812 is medium with a severity value of 5.4.
The affected software for CVE-2021-24812 is the BetterLinks WordPress plugin version up to exclusive 1.2.6.
The CWE number associated with CVE-2021-24812 is 79.
To fix CVE-2021-24812, update the BetterLinks WordPress plugin to version 1.2.6 or higher.