CVE-2021-24954: ProfilePress < 3.2.3 - Reflected Cross-Site Scripting
The User Registration, Login Form, User Profile & Membership WordPress plugin before 3.2.3 does not sanitise and escape the ppressccdata parameter before outputting it back in an attribute of an admin dashboard page, leading to a Reflected Cross-Site Scripting issue
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the vulnerability ID for this issue?
The vulnerability ID for this issue is CVE-2021-24954.
What is the severity of CVE-2021-24954?
The severity of CVE-2021-24954 is medium.
How does the User Registration, Login Form, User Profile & Membership plugin before version 3.2.3 impact WordPress?
The User Registration, Login Form, User Profile & Membership plugin before version 3.2.3 introduces a Reflected Cross-Site Scripting issue, which can potentially allow an attacker to execute malicious scripts in the context of a user's web browser.
How can I fix the vulnerability CVE-2021-24954?
To fix the vulnerability CVE-2021-24954, it is recommended to update the User Registration, Login Form, User Profile & Membership plugin to version 3.2.3 or later.
Where can I find more information about CVE-2021-24954?
You can find more information about CVE-2021-24954 on the WordPress plugins.trac website and the WPScan vulnerability report.