First published: Mon Dec 13 2021(Updated: )
The Pixel Cat WordPress plugin before 2.6.3 does not escape some of its settings, which could allow high privilege users to perform Cross-Site Scripting attacks even when the unfiltered_html is disallowed
Credit: contact@wpscan.com
Affected Software | Affected Version | How to fix |
---|---|---|
Fatcatapps Pixel Cat | <2.6.3 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID is CVE-2021-24972.
The severity of CVE-2021-24972 is medium with a severity value of 4.8.
The affected software for CVE-2021-24972 is the Pixel Cat WordPress plugin before version 2.6.3.
CVE-2021-24972 allows high privilege users to perform Cross-Site Scripting (XSS) attacks even when the unfiltered_html is disallowed.
To fix CVE-2021-24972, update the Pixel Cat WordPress plugin to version 2.6.3 or later.