CVE-2021-24837: Passster < 3.5.5.8 - Contributor+ Stored Cross-Site Scripting
The Passster WordPress plugin before 3.5.5.8 does not escape the area parameter of its shortcode, which could allow users with a role as low as Contributor to perform Cross-Site Scripting attacks.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2021-24837?
CVE-2021-24837 is a vulnerability in the Passster WordPress plugin before version 3.5.5.8 that allows users with a role as low as Contributor to perform Cross-Site Scripting (XSS) attacks.
What is the severity of CVE-2021-24837?
CVE-2021-24837 has a severity of medium with a CVSS score of 5.4.
How does CVE-2021-24837 affect Passster WordPress plugin?
CVE-2021-24837 affects Passster WordPress plugin before version 3.5.5.8 by not properly escaping the area parameter of its shortcode, making it vulnerable to XSS attacks.
What can an attacker do with CVE-2021-24837?
An attacker exploiting CVE-2021-24837 can perform Cross-Site Scripting attacks and potentially execute malicious JavaScript code on the victim's browser.
How can I fix the CVE-2021-24837 vulnerability?
To fix the CVE-2021-24837 vulnerability, update the Passster WordPress plugin to version 3.5.5.8 or later.