CVE-2021-25105: Ivory Search < 5.4.1 - Multiple Admin+ Stored Cross-Site Scripting
Published Feb 7, 2022
·Updated
The Ivory Search WordPress plugin before 5.4.1 does not escape some of the Form settings, which could allow high privilege users to perform Cross-Site Scripting attacks even when the unfilteredhtml capability is disallowed.
Affected Software
1 affected component
Ivorysearch Ivory Search Wordpress<5.4.1
Event History
Feb 7, 2022
CVE Published
via MITRE·03:47 PM
Data Sourced
via MITRE·03:47 PM
DescriptionWeakness
Frequently Asked Questions
1
What is the severity of CVE-2021-25105?
CVE-2021-25105 is considered a high severity vulnerability due to the potential for Cross-Site Scripting attacks.
2
How do I fix CVE-2021-25105?
To fix CVE-2021-25105, update the Ivory Search WordPress plugin to version 5.4.1 or later.
3
Who is affected by CVE-2021-25105?
CVE-2021-25105 affects users of the Ivory Search WordPress plugin version prior to 5.4.1.
4
What type of attacks does CVE-2021-25105 facilitate?
CVE-2021-25105 facilitates Cross-Site Scripting attacks, allowing high privilege users to inject malicious scripts.
5
Can CVE-2021-25105 be exploited without unfiltered_html capability?
Yes, CVE-2021-25105 can be exploited even when the unfiltered_html capability is disallowed.