CVE-2021-25015: myCred < 2.4 - Reflected Cross-Site Scripting
The myCred WordPress plugin before 2.4 does not sanitise and escape the search query before outputting it back in the history dashboard page, leading to a Reflected Cross-Site Scripting issue
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is CVE-2021-25015?
CVE-2021-25015 is a vulnerability in the myCred WordPress plugin version 2.3 prior to 2.4 that allows for a Reflected Cross-Site Scripting issue.
What is the severity of CVE-2021-25015?
The severity of CVE-2021-25015 is medium with a CVSS score of 6.1.
How does CVE-2021-25015 affect myCred WordPress plugin?
CVE-2021-25015 affects the myCred WordPress plugin version 2.3 prior to 2.4 by not sanitizing and escaping the search query, leading to a Reflected Cross-Site Scripting issue.
How can I fix CVE-2021-25015?
To fix CVE-2021-25015, update the myCred WordPress plugin to version 2.4 or later.
Is there any additional information about CVE-2021-25015?
Yes, you can find more information about CVE-2021-25015 at the official WordPress plugins repository and the WPScan vulnerability database.