First published: Mon Apr 11 2022(Updated: )
Authenticated (admin or higher user role) Stored Cross-Site Scripting (XSS) vulnerability in Premio Chaty (WordPress plugin) <= 2.8.3
Credit: audit@patchstack.com
Affected Software | Affected Version | How to fix |
---|---|---|
Premio Chaty | <=2.8.3 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2021-36846 is an Authenticated Stored Cross-Site Scripting (XSS) vulnerability in the Premio Chaty WordPress plugin version 2.8.3 and below.
CVE-2021-36846 has a severity level of medium, with a CVSS score of 4.8.
The affected software of CVE-2021-36846 is Premio Chaty (WordPress plugin) version 2.8.3 and below.
To fix CVE-2021-36846, make sure to update the Premio Chaty plugin to version 2.8.4 or higher.
The CWE of CVE-2021-36846 is CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting').