CVE-2021-24900: Ninja Tables < 4.1.8 - Admin+ Stored Cross-Site Cross-Site Scripting
The Ninja Tables WordPress plugin before 4.1.8 does not sanitise and escape some of its table fields, which could allow high privilege users to perform Cross-Site Scripting attacks even when the unfilteredhtml capability is disallowed
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2021-24900?
CVE-2021-24900 is rated as a medium severity vulnerability due to its potential for Cross-Site Scripting attacks.
How do I fix CVE-2021-24900?
To fix CVE-2021-24900, update the Ninja Tables WordPress plugin to version 4.1.8 or later.
Who is affected by CVE-2021-24900?
Any user running Ninja Tables versions prior to 4.1.8 on their WordPress site is affected by CVE-2021-24900.
What type of attack does CVE-2021-24900 facilitate?
CVE-2021-24900 facilitates Cross-Site Scripting (XSS) attacks by allowing high privilege users to inject malicious scripts.
Can unfiltered_html capability impact CVE-2021-24900?
No, CVE-2021-24900 can allow Cross-Site Scripting attacks regardless of the unfiltered_html capability being disallowed.