First published: Mon Dec 13 2021(Updated: )
The User Registration, Login Form, User Profile & Membership WordPress plugin before 3.2.3 does not sanitise and escape the ppress_cc_data parameter before outputting it back in an attribute of an admin dashboard page, leading to a Reflected Cross-Site Scripting issue
Credit: contact@wpscan.com
Affected Software | Affected Version | How to fix |
---|---|---|
ProfilePress | <3.2.3 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID for this issue is CVE-2021-24954.
The severity of CVE-2021-24954 is medium.
The User Registration, Login Form, User Profile & Membership plugin before version 3.2.3 introduces a Reflected Cross-Site Scripting issue, which can potentially allow an attacker to execute malicious scripts in the context of a user's web browser.
To fix the vulnerability CVE-2021-24954, it is recommended to update the User Registration, Login Form, User Profile & Membership plugin to version 3.2.3 or later.
You can find more information about CVE-2021-24954 on the WordPress plugins.trac website and the WPScan vulnerability report.