CVE-2021-33851: XSS
A cross-site scripting (XSS) attack can cause arbitrary code (JavaScript) to run in a user's browser and can use an application as the vehicle for the attack. The XSS payload given in the "Custom logo link" executes whenever the user opens the Settings Page of the "Customize Login Image" Plugin.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2021-33851?
CVE-2021-33851 is a vulnerability that allows an attacker to run arbitrary code (JavaScript) in a user's browser through a cross-site scripting (XSS) attack.
How does CVE-2021-33851 affect WordPress Custom Login Image plugin?
CVE-2021-33851 affects version 3.4 of the WordPress Custom Login Image plugin.
How severe is CVE-2021-33851?
CVE-2021-33851 has a severity rating of medium with a CVSS score of 5.4.
How can I fix CVE-2021-33851?
To fix CVE-2021-33851, it is recommended to update the WordPress Custom Login Image plugin to a version that is not affected by the vulnerability.
Can you provide more information on CVE-2021-33851?
More information about CVE-2021-33851 can be found at the following reference: [link](https://cybersecurityworks.com/zerodays/cve-2021-33851-stored-cross-site-scripting-in-wordpress-customize-login-image.html)