CVE-2021-24932: Auto Featured Image < 3.9.3 - Reflected Cross-Site Scripting
The Auto Featured Image (Auto Post Thumbnail) WordPress plugin before 3.9.3 does not sanitise and escape the postid parameter before outputting back in an admin page within a JS block, leading to a Reflected Cross-Site Scripting issue.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2021-24932?
CVE-2021-24932 is classified as a high severity vulnerability due to its potential for Reflected Cross-Site Scripting attacks.
How do I fix CVE-2021-24932?
To fix CVE-2021-24932, update the Auto Featured Image plugin to version 3.9.3 or later.
What type of vulnerability is CVE-2021-24932?
CVE-2021-24932 is a Reflected Cross-Site Scripting (XSS) vulnerability.
Who is affected by CVE-2021-24932?
The vulnerability affects users of the Auto Featured Image plugin for WordPress versions prior to 3.9.3.
What can happen if CVE-2021-24932 is exploited?
If exploited, CVE-2021-24932 can allow attackers to execute arbitrary JavaScript code in the context of the affected user's session.