CVE-2021-36841: YITH Maintenance Mode (WordPress plugin) <= 1.3.7 - Authenticated Stored Cross-Site Scripting (XSS) vulnerability.
Authenticated Stored Cross-Site Scripting (XSS) vulnerability in YITH Maintenance Mode (WordPress plugin) versions <= 1.3.7, vulnerable parameter &yithmaintenancenewslettersubmitlabel. Possible even when unfiltered HTML is disallowed by WordPress configuration.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is CVE-2021-36841?
CVE-2021-36841 is an Authenticated Stored Cross-Site Scripting (XSS) vulnerability in the YITH Maintenance Mode WordPress plugin.
What is the severity of CVE-2021-36841?
The severity of CVE-2021-36841 is medium with a score of 5.4.
How does CVE-2021-36841 affect YITH Maintenance Mode?
CVE-2021-36841 affects YITH Maintenance Mode versions <= 1.3.7, specifically the vulnerable parameter &yith_maintenance_newsletter_submit_label.
Can CVE-2021-36841 be exploited even when HTML filtering is enabled in WordPress?
Yes, CVE-2021-36841 can be exploited even when unfiltered HTML is disallowed by the WordPress configuration.
How can I fix CVE-2021-36841 in YITH Maintenance Mode?
To fix CVE-2021-36841 in YITH Maintenance Mode, update to a version higher than 1.3.7.