CVE-2021-24908: Check & Log Email < 1.0.4 - Reflected Cross-Site Scripting
Published Nov 29, 2021
·Updated
The Check & Log Email WordPress plugin before 1.0.4 does not escape the d parameter before outputting it back in an attribute, leading to a Reflected Cross-Site Scripting
Affected Software
1 affected component
WPChill Check \& Log Email Wordpress<1.0.4
Event History
Nov 29, 2021
CVE Published
via MITRE·08:25 AM
Data Sourced
via MITRE·08:25 AM
DescriptionWeakness
Frequently Asked Questions
1
What is CVE-2021-24908?
CVE-2021-24908 is a vulnerability in the Check & Log Email WordPress plugin before version 1.0.4 that allows for Reflected Cross-Site Scripting.
2
What is the severity of CVE-2021-24908?
CVE-2021-24908 has a severity level of medium with a CVSS score of 6.1.
3
How does CVE-2021-24908 affect the Check & Log Email plugin?
CVE-2021-24908 affects the Check & Log Email plugin by allowing an attacker to execute a Reflected Cross-Site Scripting attack.
4
Is CVE-2021-24908 limited to a specific version of the Check & Log Email plugin?
Yes, CVE-2021-24908 is limited to versions before 1.0.4 of the Check & Log Email plugin.
5
How can I fix CVE-2021-24908?
To fix CVE-2021-24908, users should update to version 1.0.4 or later of the Check & Log Email plugin.