CVE-2021-24933: Dynamic Widgets <= 1.5.16 - Reflected Cross-Site Scripting
Published Feb 28, 2022
·Updated
The Dynamic Widgets WordPress plugin through 1.5.16 does not escape the prefix parameter before outputting it back in an attribute when using the termtree AJAX action (available to any authenticated users), leading to a Reflected Cross-Site Scripting issue
Affected Software
1 affected component
Bootstrapped Dynamic Widgets Wordpress<=1.5.16
Event History
Feb 28, 2022
CVE Published
via MITRE·09:06 AM
Data Sourced
via MITRE·09:06 AM
DescriptionWeakness
Frequently Asked Questions
1
What is the vulnerability ID for this issue?
The vulnerability ID for this issue is CVE-2021-24933.
2
What is the severity of CVE-2021-24933?
The severity of CVE-2021-24933 is medium with a severity value of 5.4.
3
Which software is affected by CVE-2021-24933?
The Dynamic Widgets WordPress plugin through version 1.5.16 is affected by CVE-2021-24933.
4
What is the CWE ID for this vulnerability?
The CWE ID for this vulnerability is CWE-79.
5
How can I fix CVE-2021-24933?
To fix CVE-2021-24933, update the Dynamic Widgets WordPress plugin to a version beyond 1.5.16.