CVE-2021-36846: WordPress Chaty plugin <= 2.8.3 - Authenticated Stored Cross-Site Scripting (XSS) vulnerability
Published Apr 11, 2022
·Updated
Authenticated (admin or higher user role) Stored Cross-Site Scripting (XSS) vulnerability in Premio Chaty (WordPress plugin) <= 2.8.3
Affected Software
1 affected component
Premio Chaty Wordpress<=2.8.3
Event History
Apr 11, 2022
CVE Published
via MITRE·07:37 PM
Data Sourced
via MITRE·07:37 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is CVE-2021-36846?
CVE-2021-36846 is an Authenticated Stored Cross-Site Scripting (XSS) vulnerability in the Premio Chaty WordPress plugin version 2.8.3 and below.
2
How severe is CVE-2021-36846?
CVE-2021-36846 has a severity level of medium, with a CVSS score of 4.8.
3
What is the affected software of CVE-2021-36846?
The affected software of CVE-2021-36846 is Premio Chaty (WordPress plugin) version 2.8.3 and below.
4
How can I fix CVE-2021-36846?
To fix CVE-2021-36846, make sure to update the Premio Chaty plugin to version 2.8.4 or higher.
5
What is the Common Weakness Enumeration (CWE) of CVE-2021-36846?
The CWE of CVE-2021-36846 is CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting').