CVE-2021-36826: WordPress WP Project Manager plugin <= 2.4.13 - Stored Cross-Site Scripting (XSS) vulnerability
Published Apr 4, 2022
·Updated
Authenticated (subscriber or higher user role if allowed to access projects) Stored Cross-Site Scripting (XSS) vulnerability in weDevs WP Project Manager plugin <= 2.4.13 versions.
Affected Software
1 affected component
weDevs Wp Project Manager Wordpress<2.4.14
Remediation
Information
Update to 2.4.14 or higher version.
Event History
Apr 4, 2022
CVE Published
via MITRE·07:46 PM
Data Sourced
via MITRE·07:46 PM
RemedyDescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2021-36826?
The severity of CVE-2021-36826 is medium with a severity value of 5.4.
2
How does CVE-2021-36826 affect weDevs WP Project Manager plugin?
CVE-2021-36826 affects weDevs WP Project Manager plugin versions up to and including 2.4.13.
3
What is the CWE ID for CVE-2021-36826?
The CWE ID for CVE-2021-36826 is 79.
4
Is authentication required to exploit CVE-2021-36826?
Yes, authentication is required to exploit CVE-2021-36826.
5
Are there any patches available for CVE-2021-36826?
Yes, there is a patch available for CVE-2021-36826. Please refer to the reference link for more information.