CVE-2021-24902: Typebot < 1.4.3 - Admin+ Stored Cross Site Scripting
The Typebot | Build beautiful conversational forms WordPress plugin before 1.4.3 does not sanitise and escape the Publish ID setting, which could allow high privilege users to perform Cross-Site Scripting attacks even when the unfilteredhtml capability is disallowed.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2021-24902?
CVE-2021-24902 is considered a critical vulnerability due to the potential for high privilege users to execute Cross-Site Scripting attacks.
How do I fix CVE-2021-24902?
To fix CVE-2021-24902, update the Typebot WordPress plugin to version 1.4.3 or higher.
Who is affected by CVE-2021-24902?
CVE-2021-24902 affects users of the Typebot WordPress plugin versions prior to 1.4.3.
What types of attacks can CVE-2021-24902 facilitate?
CVE-2021-24902 can facilitate Cross-Site Scripting attacks, allowing malicious scripts to run in the context of the affected site.
Can low privilege users exploit CVE-2021-24902?
No, CVE-2021-24902 requires high privilege users to exploit the vulnerability.