CVE-2021-24939: LoginWP < 3.0.0.5 - Reflected Cross-Site Scripting
The LoginWP (Formerly Peter's Login Redirect) WordPress plugin before 3.0.0.5 does not sanitise and escape the rulloginurl and rullogouturl parameter before outputting them back in attributes in an admin page, leading to a Reflected Cross-Site Scripting issue
Affected Software
Event History
Frequently Asked Questions
What is CVE-2021-24939?
CVE-2021-24939 is a vulnerability in the LoginWP (formerly Peter's Login Redirect) WordPress plugin before version 3.0.0.5, which allows for a Reflected Cross-Site Scripting attack.
How severe is CVE-2021-24939?
The severity of CVE-2021-24939 is medium with a CVSS score of 6.1.
Which software is affected by CVE-2021-24939?
The LoginWP (formerly Peter's Login Redirect) WordPress plugin versions up to and excluding 3.0.0.5 are affected by CVE-2021-24939.
What is the Common Weakness Enumeration (CWE) for CVE-2021-24939?
The CWE for CVE-2021-24939 is CWE-79, which refers to Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting').
Is there a fix available for CVE-2021-24939?
Yes, the fix for CVE-2021-24939 is to update the LoginWP plugin to version 3.0.0.5 or higher.