CVE-2021-24975: NextScripts: Social Networks Auto-Poster < 4.3.24 - Unauthenticated Stored XSS
Published Feb 1, 2022
·Updated
The NextScripts: Social Networks Auto-Poster WordPress plugin before 4.3.24 does not sanitise and escape logged requests before outputting them in the related admin dashboard, leading to an Unauthenticated Stored Cross-Site Scripting issue
Affected Software
1 affected component
NextScripts Social Networks Auto Poster Wordpress<4.3.24
Remediation
Patch Available
Event History
Feb 1, 2022
CVE Published
via MITRE·12:21 PM
Data Sourced
via MITRE·12:21 PM
DescriptionWeakness
Frequently Asked Questions
1
What is the severity of CVE-2021-24975?
CVE-2021-24975 is classified as a high-severity vulnerability due to its potential for Unauthenticated Stored Cross-Site Scripting.
2
How do I fix CVE-2021-24975?
To fix CVE-2021-24975, update the NextScripts: Social Networks Auto-Poster plugin to version 4.3.24 or later.
3
What type of vulnerability is CVE-2021-24975?
CVE-2021-24975 is an Unauthenticated Stored Cross-Site Scripting vulnerability.
4
What versions of the NextScripts plugin are affected by CVE-2021-24975?
CVE-2021-24975 affects all versions of the NextScripts: Social Networks Auto-Poster plugin prior to 4.3.24.
5
Is user authentication required to exploit CVE-2021-24975?
No, CVE-2021-24975 can be exploited without authentication.