CVE-2021-36845: YITH Maintenance Mode (WordPress plugin) <= 1.3.8 - Multiple Authenticated Stored Cross-Site Scripting (XSS) vulnerabilities
Multiple Authenticated Stored Cross-Site Scripting (XSS) vulnerabilities in YITH Maintenance Mode (WordPress plugin) versions <= 1.3.8, there are 46 vulnerable parameters that were missed by the vendor while patching the 1.3.7 version to 1.3.8. Vulnerable parameters: 1 - "Newsletter" tab, &yithmaintenancenewslettersubmitlabel parameter: payload should start with a single quote (') symbol to break the context, i.e.: NOTIFY ME' autofocus onfocus=alert(/Visse/);// v=' - this payload will be auto triggered while admin visits this page/tab. 2 - "General" tab issues, vulnerable parameters: &yithmaintenancemessage, &yithmaintenancecustomstyle, &yithmaintenancemascotte, &yithmaintenancetitlefont[size], &yithmaintenancetitlefont[family], &yithmaintenancetitlefont[color], &yithmaintenanceparagraphfont[size], &yithmaintenanceparagraphfont[family], &yithmaintenanceparagraphfont[color], &yithmaintenancebordertop. 3 - "Background" tab issues, vulnerable parameters: &yithmaintenancebackgroundimage, &yithmaintenancebackgroundcolor. 4 - "Logo" tab issues, vulnerable parameters: &yithmaintenancelogoimage, &yithmaintenancelogotagline, &yithmaintenancelogotaglinefont[size], &yithmaintenancelogotaglinefont[family], &yithmaintenancelogotaglinefont[color]. 5 - "Newsletter" tab issues, vulnerable parameters: &yithmaintenancenewsletteremailfont[size], &yithmaintenancenewsletteremailfont[family], &yithmaintenancenewsletteremailfont[color], &yithmaintenancenewslettersubmitfont[size], &yithmaintenancenewslettersubmitfont[family], &yithmaintenancenewslettersubmitfont[color], &yithmaintenancenewslettersubmitbackground, &yithmaintenancenewslettersubmitbackgroundhover, &yithmaintenancenewslettertitle, &yithmaintenancenewsletteraction, &yithmaintenancenewsletteremaillabel, &yithmaintenancenewsletteremailname, &yithmaintenancenewslettersubmitlabel, &yithmaintenancenewsletterhiddenfields. 6 - "Socials" tab issues, vulnerable parameters: &yithmaintenancesocialsfacebook, &yithmaintenancesocialstwitter, &yithmaintenancesocialsgplus, &yithmaintenancesocialsyoutube, &yithmaintenancesocialsrss, &yithmaintenancesocialsskype, &yithmaintenancesocialsemail, &yithmaintenancesocialsbehance, &yithmaintenancesocialsdribble, &yithmaintenancesocialsflickr, &yithmaintenancesocialsinstagram, &yithmaintenancesocialspinterest, &yithmaintenancesocialstumblr, &yithmaintenancesocialslinkedin.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2021-36845?
The severity of CVE-2021-36845 is medium with a severity value of 4.8.
Which version of YITH Maintenance Mode is affected by CVE-2021-36845?
YITH Maintenance Mode versions <= 1.3.8 are affected by CVE-2021-36845.
How many vulnerable parameters are there in YITH Maintenance Mode for CVE-2021-36845?
There are 46 vulnerable parameters in YITH Maintenance Mode for CVE-2021-36845.
What is the Common Weakness Enumeration (CWE) ID for CVE-2021-36845?
The Common Weakness Enumeration (CWE) ID for CVE-2021-36845 is CWE-79 (Cross-Site Scripting).
Where can I find more information about CVE-2021-36845?
You can find more information about CVE-2021-36845 at the following references: [Reference 1](https://patchstack.com/database/vulnerability/yith-maintenance-mode/wordpress-yith-maintenance-mode-plugin-1-3-8-multiple-authenticated-stored-cross-site-scripting-xss-vulnerabilities), [Reference 2](https://wordpress.org/plugins/yith-maintenance-mode/#developers)