First published: Mon Aug 16 2021(Updated: )
The Media Usage WordPress plugin is vulnerable to Reflected Cross-Site Scripting via the id parameter in the ~/mmu_admin.php file which allows attackers to inject arbitrary web scripts, in versions up to and including 0.0.4.
Credit: security@wordfence.com
Affected Software | Affected Version | How to fix |
---|---|---|
Meowapps Media Usage | <=0.0.4 |
Uninstall the plugin
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2021-34652 is classified as a Cross-Site Scripting vulnerability, which can allow attackers to execute arbitrary scripts on a user's browser.
To fix CVE-2021-34652, update the Media Usage WordPress plugin to version 0.0.5 or later.
CVE-2021-34652 affects all versions of the Media Usage plugin up to and including 0.0.4.
CVE-2021-34652 can potentially allow attackers to inject malicious scripts, compromising user sessions and data.
CVE-2021-34652 can be exploited easily by an attacker who crafts a malicious URL containing the vulnerable id parameter.