CVE-2021-24956: Blog2Social < 6.8.7 - Reflected Cross-Site Scripting
Published Dec 21, 2021
·Updated
The Blog2Social: Social Media Auto Post & Scheduler WordPress plugin before 6.8.7 does not sanitise and escape the b2sShowByDate parameter before outputting it back in an admin page, leading to a Reflected Cross-Site Scripting issue
Affected Software
1 affected component
Adenion Blog2social Wordpress<6.8.7
Event History
Dec 21, 2021
CVE Published
via MITRE·08:45 AM
Data Sourced
via MITRE·08:45 AM
DescriptionWeakness
Frequently Asked Questions
1
What is the vulnerability ID of this issue?
The vulnerability ID of this issue is CVE-2021-24956.
2
What is the affected software?
The affected software is the Blog2Social: Social Media Auto Post & Scheduler WordPress plugin version up to 6.8.7.
3
What is the severity of CVE-2021-24956?
The severity of CVE-2021-24956 is medium with a CVSS score of 6.1.
4
What is the CWE category of this vulnerability?
This vulnerability belongs to the CWE category 79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting').
5
How do I fix CVE-2021-24956?
To fix CVE-2021-24956, update the Blog2Social plugin to version 6.8.7 or newer, which includes a fix for the vulnerability.