CVE-2021-25071: Akismet Privacy Policies <= 2.0.1 - Reflected Cross-Site Scripting
Published Mar 28, 2022
·Updated
The WordPress plugin through 2.0.1 does not sanitise and escape the translation parameter before outputting it back in an admin page, leading to a Reflected Cross-Site Scripting
Affected Software
1 affected component
Inpsyde Akismet Privacy Policies Wordpress<=2.0.1
Event History
Mar 28, 2022
CVE Published
via MITRE·05:22 PM
Data Sourced
via MITRE·05:22 PM
DescriptionWeakness
Frequently Asked Questions
1
What is the severity of CVE-2021-25071?
CVE-2021-25071 is classified as a medium severity vulnerability due to its potential for reflected cross-site scripting attacks.
2
How do I fix CVE-2021-25071?
To fix CVE-2021-25071, update the Akismet Privacy Policies plugin to version 2.0.2 or later.
3
Who is affected by CVE-2021-25071?
CVE-2021-25071 affects users of the Akismet Privacy Policies plugin version 2.0.1 and earlier on WordPress sites.
4
What type of vulnerability is CVE-2021-25071?
CVE-2021-25071 is a reflected cross-site scripting (XSS) vulnerability.
5
What can attackers do with CVE-2021-25071?
Attackers can exploit CVE-2021-25071 to execute arbitrary scripts in the context of an admin user's session, potentially compromising the site.