CVE-2021-25104: Ocean Extra < 1.9.5 - Reflected Cross-Site Scripting
Published Jun 20, 2022
·Updated
The Ocean Extra WordPress plugin before 1.9.5 does not escape generated links which are then used when the OceanWP is active, leading to a Reflected Cross-Site Scripting issue
Affected Software
1 affected component
Oceanwp Ocean Extra WordPress<1.9.5
Event History
Jun 20, 2022
CVE Published
via MITRE·10:25 AM
Data Sourced
via MITRE·10:25 AM
DescriptionWeakness
Frequently Asked Questions
1
What is the vulnerability ID for this issue?
The vulnerability ID for this issue is CVE-2021-25104.
2
What is the severity of CVE-2021-25104?
The severity of CVE-2021-25104 is medium.
3
Which software is affected by CVE-2021-25104?
The Ocean Extra WordPress plugin before version 1.9.5 is affected by CVE-2021-25104.
4
What is the impact of CVE-2021-25104?
CVE-2021-25104 allows for a Reflected Cross-Site Scripting issue.
5
How can I fix CVE-2021-25104?
To fix CVE-2021-25104, update the Ocean Extra WordPress plugin to version 1.9.5 or later.